Vulnerability Intelligence Report
Undisclosed RCE in Zammad v6.3 and higher
CVE-2026-102489
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
CISA KEV
SSVC: Active Exploitation
Automatable
CVSS Base Score
8.7
HIGH
EPSS Probability:0.58%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-384 ↗CWE-384 Session Fixation
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Zammad GmbH | Zammad | * < 6.3.0 (unknown), 6.3.0 < 6.5.4 (affected), 7.0.0 < * (unaffected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Dutch Institute for Vulnerability Disclosure (DIVD) · Researcher · Netherlands |
| Reserved | 2026-09-29T09:46:12 |
| Published | 2026-09-30T16:21:19 |
| Patch Date | 2026-09-29 |
| Last Updated | 2026-10-02T19:58:24 |
Community Chatter & Buzz