---
id: CVE-2024-33668
title: An issue was discovered in Zammad before 6.3.0
summary: >-
  An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses
  insecure, partially guessable FormIDs to identify content. An attacker could
  try to brute force them to upload malicious content to article drafts they
  have no …
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-639
vendor: zammad
product: zammad
affected:
  - 'zammad >= 6.2.0, < 6.3.0'
  - zammad = 6.3.0
patched:
  - zammad 6.3.0
published: '2024-04-26'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T20:17:20.507'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-33668'
references:
  - url: 'https://a7.de/fue/advisories/cve-2024-33668/'
    label: cve@mitre.org
  - url: 'https://zammad.com/en/advisories/zaa-2024-02'
    label: cve@mitre.org
  - url: 'https://zammad.com/en/advisories/zaa-2024-02'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2024-06-03T17:24:14.827675Z'
epss: 0.00448
epssPercentile: 0.36188
ingestedAt: '2026-09-16T20:03:30.761Z'
---

## Overview

An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to.

## Affected

- `zammad >= 6.2.0, < 6.3.0`
- `zammad = 6.3.0`

## Remediation

Upgrade past the affected range:

- `zammad 6.3.0`
