Executive brief
Zammad is an open-source helpdesk and customer support platform used by businesses to manage client communications. A security flaw allows unauthorized individuals to access sensitive internal data by visiting a specific setup-related web address that should have been deactivated after installation. This could lead to the exposure of private organizational information to anyone on the internet.
Technical details
An improper access control vulnerability exists in Zammad's 'getting_started_controller'. The 'getting started' endpoint remains accessible to unauthenticated remote attackers even after the initial system setup is finalized. By sending a specially crafted network request to this endpoint, an attacker can retrieve sensitive internal entity data without any prior authorization or user interaction. The issue is rooted in insufficient restriction of the setup-related resources. This vulnerability is resolved in Zammad versions 7.0.1 and 6.5.4.
Affected products
- Zammad Zammad < 6.5.4, >= 7.0.0-alpha, < 7.0.1
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory
- 2026-04-08: patched