OVERVIEW CVE-2026-34837 is an authorization bypass vulnerability in Zammad, an open source web-based helpdesk and customer support system. The flaw exists in the REST API endpoint POST /api/v1/ai_assistance/text_tools/:id in versions prior to 7.0.1. The vulnerability allows authenticated users to supply context data (such as group or organization information) to AI prompts without proper authorization validation, potentially exposing data that the user should not have access to. SEVERITY This is a medium-severity vulnerability with a CVSS score of 4.3. The attack requires network access and low privileges (ticket.agent permission), but no user interaction is needed. The impact is limited to confidentiality breach, as the vulnerability only results in unauthorized data disclosure without affecting system integrity or availability. An attacker could access sensitive organizational or group information through the AI assistance feature that they are not authorized to view. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability has not been added to CISA's Known Exploited Vulnerabilities catalog, and no public exploit code is reported to be available. The EPSS score of 0.0003 indicates very low probability of exploitation in the wild, suggesting limited community attention and low threat actor interest at this time. The patch is available in version 7.0.1, and affected organizations should prioritize updating to remediate this authorization flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0.0CPE matchmatch criteria | cpe:2.3:a:zammad:zammad:7.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.