CVE-2026-34837

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, he REST endpoint POST /api/v1/ai_assistance/text_tools/:id contains an authorization failure. Context data (e.g., a group or organization) supplied to be used in the AI prompt were not checked if they are accessible for the current user. This leads to having data present in the AI prompt that were not authorized before being used. A user needs to have ticket.agent permission to be able to use the provided context data. This vulnerability is fixed in 7.0.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zammad:zammad:7.0.0:*:*:*:*:*:*:*

History

17 Apr 2026, 15:51

Type Values Removed Values Added
References () https://github.com/zammad/zammad/security/advisories/GHSA-89vv-6639-wcv8 - Third Party Advisory () https://github.com/zammad/zammad/security/advisories/GHSA-89vv-6639-wcv8 - Vendor Advisory

17 Apr 2026, 14:48

Type Values Removed Values Added
References () https://github.com/zammad/zammad/security/advisories/GHSA-89vv-6639-wcv8 - () https://github.com/zammad/zammad/security/advisories/GHSA-89vv-6639-wcv8 - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CPE cpe:2.3:a:zammad:zammad:7.0.0:*:*:*:*:*:*:*
First Time Zammad zammad
Zammad

08 Apr 2026, 19:25

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-08 19:25

Updated : 2026-04-17 15:51


NVD link : CVE-2026-34837

Mitre link : CVE-2026-34837

CVE.ORG link : CVE-2026-34837


JSON object : View

Products Affected

zammad

  • zammad
CWE
CWE-862

Missing Authorization