Junglewise Threat Intelligence

CVE-2026-34723: Zammad improper access control in getting_started_controller

CVE-2026-34723 · Severity: high · CVSS 7.5 · Published 2026-04-08

Technologies: Zammad. Vendors: Zammad.

Executive brief

Zammad is an open-source helpdesk and customer support platform used by businesses to manage client communications. A security flaw allows unauthorized individuals to access sensitive internal data by visiting a specific setup-related web address that should have been deactivated after installation. This could lead to the exposure of private organizational information to anyone on the internet.

Technical details

An improper access control vulnerability exists in Zammad's 'getting_started_controller'. The 'getting started' endpoint remains accessible to unauthenticated remote attackers even after the initial system setup is finalized. By sending a specially crafted network request to this endpoint, an attacker can retrieve sensitive internal entity data without any prior authorization or user interaction. The issue is rooted in insufficient restriction of the setup-related resources. This vulnerability is resolved in Zammad versions 7.0.1 and 6.5.4.

Affected products

  • Zammad Zammad < 6.5.4, >= 7.0.0-alpha, < 7.0.1

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory
  • 2026-04-08: patched

References

Related threats