A vulnerability identified as problematic has been detected in Zulip. This issue affects some unknown processing of the component API Endpoint. The manipulation leads to incorrect authorization.

This vulnerability is uniquely identified as CVE-2026-25741. The attack is possible to be carried out remotely. No exploit exists.

Applying a patch is the recommended action to fix this issue.