CVE-2026-34724Disclosure(zammad / zammad)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vulnerability which leads to RCE via AI Agent exists. Impact is limited to environments where an attacker can control or influence type_enrichment_data (typically high-privilege administrative configuration). This vulnerability is fixed in 7.0.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-1336

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zammad

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-08); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
zammad

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-08: 1Mentions · 2026-04-09: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-09: 104-0804-09
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34724 Server-Side Template Injection Remote Code Execution in Zammad Before 7.0.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34724

    Post summary

    The text announces a Server‑Side Template Injection that enables remote code execution in Zammad versions earlier than 7.0.1, but it does not provide PoC code, exploit tools, or patch information.

    0000043
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34724 Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vulnerability which leads to RCE via AI Agent ex… https://www.cve.org/CVERecord?id=CVE-2026-34724

    Post summary

    The post describes a server‑side template injection in Zammad 7.0.1 and newer versions, which can lead to remote code execution, but does not provide evidence of active exploitation, a PoC, or a patch.

    00000102
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appzammadzammad7.0.0--

Explore more