Junglewise Threat Intelligence

CVE-2026-34782: Zammad missing authorization in AI assistance text tools

CVE-2026-34782 · Severity: medium · CVSS 4.3 · Published 2026-04-08

Technologies: Zammad. Vendors: Zammad.

Executive brief

Zammad is an open-source customer support and helpdesk platform. A security flaw was identified where the system failed to verify if a user had the necessary permissions to use AI-powered text tools. This could allow unauthorized users to access and use these AI features in contexts where they should be restricted, potentially leading to unauthorized data processing or increased operational costs.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Zammad AI assistance controller. The REST endpoint 'POST /api/v1/ai_assistance/text_tools/:id' failed to perform an authorization check to ensure the requesting user possessed the required 'ticket.agent' permission. An authenticated attacker with low privileges can exploit this over the network to utilize AI text tools in unauthorized situations. The vulnerability is resolved in versions 7.0.1 and 6.5.4 by implementing the necessary permission checks.

Affected products

  • Zammad Zammad >= 7.0.0, < 7.0.1; < 6.5.4

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory
  • 2026-04-08: patched

References

Related threats