Loading
In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that they have no permission for.
Cite this page
CVE-2025-32357. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2025-32357
Use CWE-288, Zammad vendor hub and Zammad product page to widen CVE-2025-32357 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-34724, CVE-2026-34723 and CVE-2026-34719 for nearby disclosures in the same product family.