CVE-2026-34722: Zammad is missing authorization in ticket create endpoint
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the used endpoint for ticket creation was missing authorization if the related parameter for adding links is used. This vulnerability is fixed in 7.0.1 and 6.5.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zammadto a version that resolves this vulnerability.Fixed in 7.0.1 - Upgrade
Upgrade
Zammadto a version that resolves this vulnerability.Fixed in 6.5.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34722?
CVE-2026-34722 has been classified as a high severity vulnerability due to the risk of unauthorized ticket creation.
How do I fix CVE-2026-34722?
To fix CVE-2026-34722, upgrade Zammad to version 7.0.1 or 6.5.4 or later.
What systems are affected by CVE-2026-34722?
CVE-2026-34722 affects Zammad versions prior to 7.0.1 and 6.5.4.
What type of vulnerability is CVE-2026-34722?
CVE-2026-34722 is an authorization vulnerability in the ticket creation endpoint of Zammad.
Can CVE-2026-34722 lead to data exposure?
Yes, CVE-2026-34722 can lead to unauthorized access and potentially expose sensitive ticket data.