{"id":"CVE-2026-13229","published":"2026-08-04T19:16:41.890","lastModified":"2026-08-07T13:16:46.993","description":"Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://fluidattacks.com/es/advisories/chicago","tags":[]},{"url":"https://github.com/zammad/zammad","tags":[]},{"url":"https://github.com/zammad/zammad/releases/tag/7.1.2","tags":[]},{"url":"https://github.com/zammad/zammad/security/advisories/GHSA-374g-4f73-g7m7","tags":[]}],"exploitRefs":[{"url":"https://github.com/zammad/zammad","tags":[]},{"url":"https://github.com/zammad/zammad/releases/tag/7.1.2","tags":[]},{"url":"https://github.com/zammad/zammad/security/advisories/GHSA-374g-4f73-g7m7","tags":[]}],"hasPoc":true,"ai":null}