In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that they have no permission for.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-32357.json"