Server-Side Template Injection to RCE in Zammad's AI Agent (CVE-2026-34724)

How Zammad’s brand-new AI Agent feature routed admin-controlled input into an ERB template rendered with trusted: true, yielding remote code execution as the application user.

June 3, 2026 · 4 min · k0x1c

Direct-Request SSRF via Zammad Webhooks (CVE-2026-34719)

A webhook endpoint that accepted internal IPs with no range validation, turned into a clean data-exfiltration primitive by Zammad’s own HTTP logs.

June 3, 2026 · 3 min · k0x1c

Stored data: URI XSS / Phishing via Zammad's HTML Sanitizer (CVE-2026-34718)

A one-scheme gap in Zammad’s link sanitizer let a data:text/html anchor survive into stored ticket articles — a stored phishing primitive delivered through inbound email.

June 3, 2026 · 3 min · k0x1c