Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The bug is also present in version 7.0.0 to version 7.1.2, but not exploitable due to changes in the underlying framework.
⚠️ Actively exploited — CISA KEV
This CVE was added to CISA's Known Exploited Vulnerabilities catalog on 2026-10-02. It is confirmed exploited in the wild and must be patched as a priority.
Remediation deadline (US federal agencies): 2026-10-05
CVSS v3.1 Score
9.8
/ 10.0
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Information
- Published
- 30 sept. 2026
- Updated
- 7 oct. 2026
- Status
- Analyzed
- Source
- csirt@divd.nl
Affected products
zammad zammad
Versions : 6.5.4
Weaknesses (CWE)
CWE-384CWE-384
References (5)
- https://csirt.divd.nl/CVE-2026-102489Third Party Advisory
- https://csirt.divd.nl/DIVD-2026-00015Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-102489US Government Resource
Similar CVEs
Other vulnerabilities of type CWE-384
Loading…
Monitor your products
Get automatic alerts for every new CVE affecting your equipment.