High severity7.5NVD Advisory· Published Apr 8, 2026· Updated Apr 17, 2026
CVE-2026-34723
CVE-2026-34723
Description
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, unauthenticated remote attackers were able to access the getting started endpoint to get access to sensitive internal entity data, even after the system setup was completed. This vulnerability is fixed in 7.0.1 and 6.5.4.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/zammad/zammad/security/advisories/GHSA-hcm9-ch62-5727nvdVendor Advisory
News mentions
0No linked articles in our index yet.