CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-102489 — Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability tha...

·Source: NIST NVD

Updated:

Executive Summary

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

Analysis

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions. CVSS Score: 9.8. Published: 2026-09-30T17:16:40.550.

Indicators of Compromise (1)

CVE (1)
CVE-2026-102489
Source Attribution

Originally published by NIST NVD on Sep 30, 2026. Verified by: NIST.

Related Threats