CVE-2026-34724
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vul
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vulnerability which leads to RCE via AI Agent exists. Impact is limited to environments where an attacker can control or influence type_enrichment_data (typically high-privilege administrative configuration).
This vulnerability is fixed in 7.0.1.
HIGH · CVSS 7.2
EPSS 0.00065
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0