Medium severity6.5NVD Advisory· Published May 2, 2023· Updated Jun 17, 2026
CVE-2023-29868
CVE-2023-29868
Description
Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and customer roles could perform unauthorized changes on articles where they only have customer permissions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
1- zammad.com/en/advisories/zaa-2023-01nvdVendor Advisory
News mentions
0No linked articles in our index yet.