Junglewise Threat Intelligence

CVE-2026-34248: Zammad improper access control in ticket detail view

CVE-2026-34248 · Severity: medium · CVSS 5.7 · Published 2026-04-08

Technologies: Zammad. Vendors: Zammad.

Executive brief

Zammad is an open-source helpdesk and customer support platform. A security flaw allowed customers within 'shared organizations' to view internal ticket data that should have been hidden, such as ticket priority levels and internal administrative notes. While unauthorized users could see this sensitive information when viewing tickets from other members of their organization, they were not able to modify the data.

Technical details

An improper access control vulnerability (CWE-284) exists in Zammad's ticket detail view for shared organizations. When a customer user opens a ticket belonging to another user within the same shared organization, the system fails to filter internal-only fields. This results in the disclosure of sensitive attributes such as ticket priority and custom internal ticket attributes. The attack requires low privileges (a valid customer account within a shared organization) and some user interaction. The vulnerability is limited to information disclosure as affected users cannot modify the exposed fields. The issue is resolved in version 7.0.1.

Affected products

  • Zammad Zammad >= 7.0.0, < 7.0.1

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory
  • 2026-04-08: patched: Fixed in version 7.0.1

References

Related threats