CVE-2025-32357: Zammad
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that they have no permission for.
Affected products
- Zammad Zammad: from 6.4.0, before 6.4.2 (fixed in 6.4.2)
Published 2025-04-05. Last modified 2026-06-17.