PT-2026-98899 · Zammad · Zammad
CVE-2026-56724
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Zammad versions prior to 7.0.2
Description
An issue with permission checks in the knowledge base management area allows users with limited read permissions to interact with items outside their assigned access scope due to incomplete data validation for linked items.
Recommendations
Update to version 7.0.2.
Exploit
Fix
Missing Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zammad