CVE-2026-34723: Zammad has incorrect access control in getting_started_controller
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, unauthenticated remote attackers were able to access the getting started endpoint to get access to sensitive internal entity data, even after the system setup was completed. This vulnerability is fixed in 7.0.1 and 6.5.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zammadto a version that resolves this vulnerability.Fixed in 7.0.1 - Upgrade
Upgrade
Zammadto a version that resolves this vulnerability.Fixed in 6.5.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34723?
CVE-2026-34723 has a high severity rating due to its potential for remote unauthenticated access to sensitive data.
How do I fix CVE-2026-34723?
To mitigate CVE-2026-34723, upgrade Zammad to version 7.0.1 or 6.5.4 or later.
What kind of data can be accessed due to CVE-2026-34723?
CVE-2026-34723 allows attackers to access sensitive internal entity data from the getting started endpoint.
Which versions of Zammad are affected by CVE-2026-34723?
CVE-2026-34723 affects Zammad versions prior to 7.0.1 and 6.5.4.
Can CVE-2026-34723 be exploited remotely?
Yes, CVE-2026-34723 can be exploited by remote unauthenticated attackers.