Executive brief
Zammad is an open-source helpdesk and customer support platform. A security flaw in its AI assistance feature could allow a support agent to access sensitive organizational or group data they are not authorized to see. By including unauthorized data in an AI prompt, an attacker could potentially leak internal information that should be restricted to specific teams.
Technical details
A missing authorization check (CWE-862) exists in the Zammad AI assistance controller, specifically the REST endpoint 'POST /api/v1/ai_assistance/text_tools/:id'. The application fails to verify if the current user has permission to access context data (such as group or organization details) supplied in the AI prompt request. An attacker with 'ticket.agent' permissions can exploit this to include and view data they are not authorized to access. The vulnerability is present in version 7.0.0 and was addressed in version 7.0.1.
Affected products
- Zammad Zammad >= 7.0.0, < 7.0.1
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory
- 2026-04-08: patched