CVE-2026-13229: Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint.
Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-13229
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-13229 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [hoch] Zammad: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Zammad: Mehrere Schwachstellencert-bund
Recent advisories for Zammad
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[UPDATE] [hoch] Zammad: Mehrere Schwachstellencert-bund · 2026-08-05
- high[UPDATE] [hoch] Zammad: Mehrere Schwachstellencert-bund · 2026-08-05
More from NVD Recent CVEs
- unknownCVE-2026-70474: Flowise is a drag-and-drop user interface for building customized large language model (LLM) f…2026-08-04
- unknownCVE-2026-70473: Flowise is a drag-and-drop user interface for building customized large language model (LLM) f…2026-08-04
- unknownCVE-2026-70472: Flowise is a drag & drop user interface to build a customized large language model flow. Prior…2026-08-04
- unknownCVE-2026-70471: Flowise is a drag-and-drop user interface for building customized large language model (LLM) f…2026-08-04
- mediumCVE-2026-69704: Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate databas…2026-08-04