CVE-2026-102489 Details
Description
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
A session hijacking vulnerability has been identified in Zammad versions 6.3.0 prior to 6.5.4, allowing for remote code execution as the Zammad user. While this vulnerability also exists in Zammad versions 7.0.0 to 7.1.3, it is not exploitable due to environmental conditions.
Users are advised to upgrade to Zammad version 7 or take the application offline. Zammad has been notified of the vulnerability and is working on a fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://csirt.divd.nl/CVE-2026-102489 | [email protected] | AdvisoryTechnical Description |
| https://csirt.divd.nl/DIVD-2026-00015 | [email protected] | BundleTechnical Description |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Zammad GmbH Zammad | >= 6.3.0, < 6.5.4 (semver) >= 7.0.0, < 7.1.4 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion