CVE-2026-34782: Zammad has improper access control in AI assistance controller for text tools
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the REST endpoint POST /api/v1/aiassistance/texttools/:id was not checking if a user is privileged to use the text tool, resulting in being able to use it in all situations. This vulnerability is fixed in 7.0.1 and 6.5.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zammadto a version that resolves this vulnerability.Fixed in 7.0.1 - Upgrade
Upgrade
Zammadto a version that resolves this vulnerability.Fixed in 6.5.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34782?
CVE-2026-34782 is rated as a medium severity vulnerability due to improper access control.
How do I fix CVE-2026-34782?
To fix CVE-2026-34782, update Zammad to version 7.0.1 or 6.5.4 or later.
What component is affected by CVE-2026-34782?
CVE-2026-34782 affects the AI assistance controller for text tools in Zammad.
What versions of Zammad are vulnerable to CVE-2026-34782?
Versions of Zammad prior to 7.0.1 and 6.5.4 are vulnerable to CVE-2026-34782.
What type of security risk does CVE-2026-34782 pose?
CVE-2026-34782 poses a security risk by allowing unauthorized users to access restricted text tools.