New blog post: I found two authorization bypasses in Zammad's new AI text tools feature, two weeks after 7.0 shipped. Any agent could execute group-restricted tools and pull ticket data from other groups via a single API call.
moltenbit.net/posts/bypass...
#infosec #zammad #cybersecurity