Description
Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint.
Published: 2026-08-04
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Zammad’s ticket article attachment cloning endpoint allows an authenticated user to clone attachments from tickets without proper authorization checks. The flaw can be exploited to view or copy sensitive documents that the attacker’s role should not access. This results in confidentiality violations, as data from unrelated tickets may be disclosed to unauthorized users, and potentially impacts the integrity of the ticket system if attachments are duplicated incorrectly.

Affected Systems

The vulnerability affects the Zammad help desk software, specifically versions around 7.1.0. Users running Zammad 7.1.0 (and the earlier 7.0.1 release referenced in the advisory) are at risk. The issue exists on all operating systems supported by Zammad, as indicated by the CPE entries for Linux, macOS, and Windows.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity vulnerability. Although no EPSS score is available, the lack of an exploit in CISA’s KEV list suggests the risk is moderate relative to other high‑severity flaws. Because the attack requires authentication, an attacker must first gain valid credentials—typically via legitimate user access or compromised accounts. Once authenticated, they can target any ticket attachment, potentially exposing private data or escalating privileges within the ticketing system.

Generated by OpenCVE AI on August 4, 2026 at 19:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Zammad to version 7.1.2 or later, which contains the fix for the improper authorization issue.
  • Ensure that only authorized roles are granted permission to clone ticket article attachments by reviewing and tightening role‑based access controls in the Zammad configuration.
  • Disable the ticket article attachment cloning functionality for non‑administrative roles by updating the 'allow_attachment_clone' setting to false, thereby preventing unauthorized access until the latest version is installed.

Generated by OpenCVE AI on August 4, 2026 at 19:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
References

Tue, 04 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint.
Title Zammad 7.0.1 - Improper authorization in ticket article attachment cloning
First Time appeared Zammad
Zammad zammad
Weaknesses CWE-862
CPEs cpe:2.3:a:zammad:zammad:*:*:linux:*:*:*:*:*
cpe:2.3:a:zammad:zammad:*:*:macos:*:*:*:*:*
cpe:2.3:a:zammad:zammad:*:*:windows:*:*:*:*:*
Vendors & Products Zammad
Zammad zammad
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published:

Updated: 2026-08-07T12:56:21.756Z

Reserved: 2026-06-24T17:08:23.072Z

Link: CVE-2026-13229

cve-icon Vulnrichment

Updated: 2026-08-07T12:56:18.890Z

cve-icon NVD

Status : Received

Published: 2026-08-04T19:16:41.890

Modified: 2026-08-07T13:16:46.993

Link: CVE-2026-13229

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T19:45:03Z

Weaknesses