← Vulnerability feed

Vulnerability record · CVE-2024-33666 · published 26 April 2024

CVE-2024-33666: Zammad improper access control vulnerability

Zammad · Zammad

An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents.

8.6 CVSS 3.1 High EPSS 0.51% · top 58.8% CWE-284 · Improper access control
8.6CVSS 3.1 base score
0.51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-33666 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-48021Zammad vulnerabilityA vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server.EPSS 0.88%9.8CVE-2022-35490Zammad improper restriction of authentication attempts vulnerabilityZammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a co…EPSS 0.87%9.8CVE-2021-42090Zammad deserialization of untrusted data vulnerabilityAn issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.EPSS 2.3%9.8CVE-2021-42094Zammad command injection vulnerabilityAn issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.EPSS 1.9%9.8CVE-2020-26030Zammad improper authentication vulnerabilityAn issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configure…EPSS 1.4%9.8CVE-2017-5619Zammad improper authentication vulnerabilityAn issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g.…EPSS 1.5%9.8CVE-2017-6080Zammad cross-site request forgery vulnerabilityAn issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protection mechanism involving HTTP A…EPSS 0.73%9.1CVE-2024-33668Zammad insecure direct object reference vulnerabilityAn issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker c…EPSS 0.45%

Source: NIST National Vulnerability Database (record CVE-2024-33666), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.