Insufficient Permission Check in Znuny Ticketing System
CVE-2025-26846
9.8CRITICAL
What is CVE-2025-26846?
A vulnerability exists in the Znuny ticketing system prior to version 7.1.4, where insufficient permissions are enforced when the Generic Interface is utilized to modify ticket metadata. This flaw could allow unauthorized users to manipulate critical ticket information, potentially leading to data integrity issues and unauthorized access. It is crucial for organizations using this system to apply the necessary updates to mitigate this risk.
