CVE-2025-32357

MEDIUM

Zammad 6.4.0-6.4.1 - Authenticated Unauthorized Knowledge Base Content Access via API

Title source: llm
STIX 2.1

Description

In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that they have no permission for.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0021
EPSS Percentile 11.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306 CWE-288
Status published
Products (1)
zammad/zammad 6.4.0 - 6.4.2
Published Apr 05, 2025
Tracked Since Feb 18, 2026