Loading
In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server to modify the gem's files, injecting arbitrary code into Zammad processes (which run with the environment and permissions of the Zammad user).
Cite this page
CVE-2024-36078. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2024-36078
Use CWE-94, Zammad vendor hub and Zammad product page to widen CVE-2024-36078 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-34724, CVE-2026-34723 and CVE-2026-34719 for nearby disclosures in the same product family.