Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3919 articles · 228580 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-102489PATCHED
zammad · zammad

Undisclosed RCE in Zammad v6.3 and higher

Description

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The bug is also present in version 7.0.0 to version 7.1.2, but not exploitable due to changes in the underlying framework.

Affected Products

VendorProductVersions
zammadzammad6.3.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
dockerdockercve_cpe95%
linuxlinux_kernelcve_cpe95%
zammadzammadcert_advisory90%

References

  • https://csirt.divd.nl/DIVD-2026-00015(third-party-advisory)
  • https://csirt.divd.nl/CVE-2026-102489(third-party-advisory)
  • https://zammad.com/en/advisories/cve-2026-102489-cve-2026-102490(vendor-advisory)
  • https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297/2(technical-description)

Related News (11 articles)

Tier E
Reddit r/netsec6h ago
CVE-2026-102489 Deep-Dive: Zammad Session Leak to RCE
→ No new info (linked only)
Tier D
Heise Security2d ago
Warnung vor Angriffen auf Zammad und Citrix NetScaler
→ No new info (linked only)
Tier E
Hacker News5d ago
Zammad zero-days for RCE and root (CVE-2026-102489/102490)
→ No new info (linked only)
Tier D
Infosecurity Magazine5d ago
Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure
→ No new info (linked only)
Tier D
The Hacker News6d ago
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
→ No new info (linked only)
Tier E
Hacker News6d ago
Did an AI Agent Hack DIVD? The Zammad Zero-Days
→ No new info (linked only)
Tier D
Help Net Security6d ago
AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit
→ No new info (linked only)
Tier B
BSI Advisories6d ago
[NEU] [kritisch] Zammad: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode und Privilegieneskalation
→ No new info (linked only)
Tier D
SecurityWeek6d ago
Zammad Zero-Days Exploited in AI-Powered DIVD Hack
→ No new info (linked only)
Tier D
BleepingComputer6d ago
DIVD says Zammad zero-days enabled AI-driven network breach
→ No new info (linked only)
Tier C
VulDB7d ago
CVE-2026-102489 | Zammad up to 6.5.4/7.1.3 session fixiation
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV❌ No
Actively exploited❌ No
Patch available
6.5.47.0.0
PublishedSep 30, 2026
Trending Score87
Source articles11
Independent10
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-102490
Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha
Trending: 49
NONECVE-2026-56725
Zammad: Denial of Service via OTRS Import Controller
Trending: 8
NONECVE-2026-84458
Zammad: Account takeover via unverified email matching during SSO auto-link
Trending: 8
NONECVE-2026-61525
Zammad: Arbitrary File Deletion via Unvalidated Session Identifier in Long Polling Controller
Trending: 8
NONECVE-2026-56732
Zammad: Malicious input in Ticket Body Enables Session Termination
Trending: 7

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 30, 2026
Discovered by ZDM
Sep 30, 2026
Patch Available
Oct 7, 2026