Back to search

CVE-2026-102489

CRITICAL
9.8 CISA KEVNVD

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The bug is also present in version 7.0.0 to version 7.1.2, but not exploitable due to changes in the underlying framework.

Share:

⚠️ Actively exploited — CISA KEV

This CVE was added to CISA's Known Exploited Vulnerabilities catalog on 2026-10-02. It is confirmed exploited in the wild and must be patched as a priority.

Remediation deadline (US federal agencies): 2026-10-05

CVSS v3.1 Score

9.8
/ 10.0
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Information

Published
30 sept. 2026
Updated
7 oct. 2026
Status
Analyzed
Source
csirt@divd.nl

Affected products

zammad zammad
Versions : 6.5.4

Weaknesses (CWE)

CWE-384CWE-384

Similar CVEs

Other vulnerabilities of type CWE-384

Loading…

Monitor your products

Get automatic alerts for every new CVE affecting your equipment.

Enable monitoring