← Vulnerability feed

Vulnerability record · CVE-2026-102489 · published 30 September 2026

CVE-2026-102489: Zammad vulnerability

Zammad · Zammad

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

9.4 CVSS 4.0 Critical CISA KEV since 2 Oct 2026 EPSS 0.58% · top 54.2% CWE-384 · CWE-384
9.4CVSS 4.0 base score
0.58%EPSS exploitation probability, 30 days
YesIn CISA KEV, federal fix due in 0 days
1Affected product versions listed by NVD
3References
3 Oct 2026Last modified by NVD

Description

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:

Exploitation in the wild

CISA added CVE-2026-102489 to the Known Exploited Vulnerabilities catalog on 2 October 2026 as "Zammad GmbH Zammad Session Fixation Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 5 October 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-102489 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2026-102490Zammad improper privilege management vulnerabilityAll versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.KEVEPSS 0.26%9.8CVE-2022-48021Zammad vulnerabilityA vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server.EPSS 0.88%9.8CVE-2022-35490Zammad improper restriction of authentication attempts vulnerabilityZammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a co…EPSS 0.89%9.8CVE-2021-42090Zammad deserialization of untrusted data vulnerabilityAn issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.EPSS 2.3%9.8CVE-2021-42094Zammad command injection vulnerabilityAn issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.EPSS 1.9%9.8CVE-2020-26030Zammad improper authentication vulnerabilityAn issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configure…EPSS 1.4%9.8CVE-2017-5619Zammad improper authentication vulnerabilityAn issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g.…EPSS 1.5%9.8CVE-2017-6080Zammad cross-site request forgery vulnerabilityAn issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protection mechanism involving HTTP A…EPSS 0.73%

Source: NIST National Vulnerability Database (record CVE-2026-102489), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.