A vulnerability labeled as critical has been found in Zammad up to 7.0.1. The impacted element is an unknown function of the component Ticket Article Attachment Cloning. The manipulation results in improper authorization.
This vulnerability is known as CVE-2026-13229. It is possible to launch the attack remotely. No exploit is available.