๐Ÿ” CVE Alert

CVE-2026-34724

UNKNOWN 0.0

Zammad has a server-side template injection leading to RCE via AI Agent

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
13th

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vulnerability which leads to RCE via AI Agent exists. Impact is limited to environments where an attacker can control or influence type_enrichment_data (typically high-privilege administrative configuration). This vulnerability is fixed in 7.0.1.

CWE CWE-94 CWE-1336
Vendor zammad
Product zammad
Published Apr 8, 2026
Last Updated Apr 9, 2026
Stay Ahead of the Next One

Get instant alerts for zammad zammad

Be the first to know when new unknown vulnerabilities affecting zammad zammad are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

zammad / zammad
>= 7.0.0, < 7.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/zammad/zammad/security/advisories/GHSA-fg9w-jg8f-4j94