CVE-2026-34724: Zammad has a server-side template injection leading to RCE via AI Agent
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vulnerability which leads to RCE via AI Agent exists. Impact is limited to environments where an attacker can control or influence typeenrichmentdata (typically high-privilege administrative configuration). This vulnerability is fixed in 7.0.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zammadto a version that resolves this vulnerability.Fixed in 7.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34724?
CVE-2026-34724 has a high severity due to the potential for remote code execution through server-side template injection.
How do I fix CVE-2026-34724?
To fix CVE-2026-34724, upgrade to version 7.0.1 or later of Zammad.
What versions of Zammad are affected by CVE-2026-34724?
CVE-2026-34724 affects Zammad versions prior to 7.0.1, including 7.0.0.
What type of vulnerability is CVE-2026-34724?
CVE-2026-34724 is a server-side template injection vulnerability that can lead to remote code execution.
Who can exploit CVE-2026-34724?
An attacker who has access to the affected Zammad environment can exploit CVE-2026-34724.