Junglewise Threat Intelligence

CVE-2026-34724: Zammad server-side template injection in AI Agent

CVE-2026-34724 · Severity: high · CVSS 7.2 · Published 2026-04-08

Technologies: Zammad. Vendors: Zammad.

Executive brief

Zammad is an open-source helpdesk and customer support platform used by organizations to manage client communications. A security flaw in the AI Agent component could allow a high-privileged user to execute unauthorized commands on the underlying server. This could lead to a total takeover of the support system, potentially exposing sensitive customer data or disrupting helpdesk operations.

Technical details

A server-side template injection (SSTI) vulnerability exists in Zammad's AI Agent component due to improper neutralization of special elements used in a template engine (CWE-1336). The flaw is located within the handling of 'type_enrichment_data', where malicious ERB-like sequences can be injected. An attacker with high-level administrative privileges can exploit this to achieve remote code execution (RCE) in the context of the application process. The vulnerability affects version 7.0.0 and is resolved in version 7.0.1. Operators are advised to restrict administrative access and audit AI Agent records for suspicious content until the patch is applied.

Affected products

  • Zammad Zammad >= 7.0.0, < 7.0.1

Timeline

  • 2026-04-08: disclosed: Initial advisory publication
  • 2026-04-08: patched: Fixed in version 7.0.1

References

Related threats