CVE-2025-26846: Znuny
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to update ticket metadata.
Affected products
- Znuny Znuny: from 6.0.0, up to and including 6.0.48; from 6.5.1, up to and including 6.5.11; from 7.0.1, up to and including 7.1.3
Published 2025-05-12. Last modified 2026-06-17.