CVE-2024-36078: Zammad

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server to modify the gem's files, injecting arbitrary code into Zammad processes (which run with the environment and permissions of the Zammad user).

Affected products

  • Zammad Zammad: version 6.3.0 only

Published 2024-05-19. Last modified 2026-06-17.