CVE-2026-34719: Zammad has a Server-side request forgery (SSRF) via webhooks
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the webhook model was missing a proper validation for loop back addresses, or link-local addresses — only the URL scheme (HTTP/HTTPS) as well as the hostname was checked. This could end up in retrieving confidential metadata of cloud/hosting providers. The existing check is now extended and is applied when configuring webhooks as well as triggering webhook jobs. This vulnerability is fixed in 7.0.1 and 6.5.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zammadto a version that resolves this vulnerability.Fixed in 7.0.1 - Upgrade
Upgrade
Zammadto a version that resolves this vulnerability.Fixed in 6.5.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34719?
The severity of CVE-2026-34719 is classified as high due to its potential for exploitation via SSRF attacks.
How do I fix CVE-2026-34719?
To fix CVE-2026-34719, upgrade Zammad to version 7.0.1 or 6.5.4 or later.
What types of addresses are vulnerable in CVE-2026-34719?
CVE-2026-34719 is vulnerable to SSRF through loopback and link-local addresses.
What impact does CVE-2026-34719 have on affected systems?
CVE-2026-34719 can lead to unauthorized access to internal services by exploiting the SSRF vulnerability.
Which versions of Zammad are affected by CVE-2026-34719?
Zammad versions prior to 7.0.1 and 6.5.4 are affected by CVE-2026-34719.