Junglewise Threat Intelligence

CVE-2026-13229: Zammad improper authorization in ticket article attachment cloning

CVE-2026-13229 · Severity: info · Published 2026-08-04

Technologies: Zammad. Vendors: Zammad.

Executive brief

Zammad is a web-based helpdesk and customer support system. An authenticated user can exploit an improper authorization vulnerability in the ticket article attachment cloning endpoint to access or manipulate attachments belonging to other tickets or users without proper permission checks. This could lead to unauthorized access to sensitive customer information or support ticket data.

Technical details

This is an improper authorization (broken access control) vulnerability affecting Zammad versions 7.0.1 through 7.1.0 in the ticket article attachment cloning endpoint. The vulnerability exists in the attachment cloning functionality, where insufficient authorization checks allow authenticated users to clone attachments from ticket articles they do not have permission to access. While authentication is required, the endpoint fails to validate whether the user has proper permissions for the source ticket or article being cloned. An attacker can leverage this to enumerate or exfiltrate attachments from other support tickets. Patches or mitigations are not indicated in the available advisory data.

Affected products

  • Zammad Zammad 7.0.1 to 7.1.0

Timeline

  • 2026-08-04: disclosed

References

Related threats