High severity7.5NVD Advisory· Published Aug 8, 2022· Updated Jun 17, 2026
CVE-2022-35487
CVE-2022-35487
Description
Zammad 5.2.0 suffers from Incorrect Access Control. Zammad did not correctly perform authorization on certain attachment endpoints. This could be abused by an unauthenticated attacker to gain access to attachments, such as emails or attached files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4Patches
Vulnerability mechanics
References
1- zammad.com/de/advisories/zaa-2022-08nvdVendor Advisory
News mentions
0No linked articles in our index yet.