Zammad disclosed two high-severity vulnerabilities affecting its open-source helpdesk platform, including CVE-2026-34719, a server-side request forgery flaw in webhook handling, and CVE-2026-34724, a server-side template injection issue in the AI Agent component that can lead to remote code execution. The SSRF bug affects versions prior to 7.0.1 and 6.5.4 and was caused by insufficient webhook URL validation that checked only scheme and hostname, allowing requests to loopback or link-local addresses and potentially exposing confidential cloud or hosting metadata.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
A CVE entry was published for Zammad tracking a server-side template injection vulnerability in the AI Agent component that could lead to remote code execution in versions prior to 7.0.1. The advisory cited CWE-94 and CWE-1336 and noted the issue was fixed in version 7.0.1.
A CVE entry was published for Zammad tracking an SSRF issue affecting versions prior to 7.0.1 and 6.5.4. The flaw could allow retrieval of confidential metadata from cloud or hosting providers and was classified as CWE-918.
Zammad fixed a server-side template injection vulnerability in the AI Agent component that could lead to remote code execution in versions prior to 7.0.1. The issue required an attacker to control or influence type_enrichment_data, typically through high-privilege administrative configuration.
Zammad addressed a server-side request forgery vulnerability caused by insufficient validation in the webhook model, which failed to block loopback and link-local addresses. The fix extended validation during both webhook configuration and webhook job execution in versions 7.0.1 and 6.5.4.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.