CVE-2026-34724
HIGHZammad has a server-side template injection leading to RCE via AI Agent
Title source: cnaDescription
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vulnerability which leads to RCE via AI Agent exists. Impact is limited to environments where an attacker can control or influence type_enrichment_data (typically high-privilege administrative configuration). This vulnerability is fixed in 7.0.1.
Exploits (1)
Scores
CVSS v3
7.2
EPSS
0.0006
EPSS Percentile
18.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-1336
CWE-94
Status
published
Products (2)
zammad/zammad
7.0.0
zammad/zammad
>= 7.0.0, < 7.0.1
Published
Apr 08, 2026
Tracked Since
Apr 09, 2026