CVE-2024-33668: Zammad

Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to.

Affected products

  • Zammad Zammad: from 6.2.0, before 6.3.0 (fixed in 6.3.0); version 6.3.0 only

Published 2024-04-26. Last modified 2026-09-16.