Loading
Zammad 5.2.1 has a fine-grained permission model that allows to configure read-only access to tickets. However, agents were still wrongly able to perform some operations on such tickets, like adding and removing links, tags. and related answers. This issue has been fixed in 5.2.2.
Cite this page
CVE-2022-40817. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2022-40817
Use CWE-732, Zammad vendor hub and Zammad product page to widen CVE-2022-40817 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-34724, CVE-2026-34723 and CVE-2026-34719 for nearby disclosures in the same product family.