Session Hijacking Vulnerability in Zammad by Zammad GmbH
CVE-2026-102489
9.4CRITICAL
What is CVE-2026-102489?
A session hijacking vulnerability exists in Zammad versions 6.3.0 through 6.5.4, enabling potential attackers to execute remote code under the context of the zammad user. Although versions 7.0.0 to 7.1.3 are indicated to contain this vulnerability, they are not exploitable due to specific environmental restrictions. This poses significant security concerns for users deploying the affected versions.
Affected Version(s)
Zammad Linux 6.3.0 < 6.5.4
Zammad Linux 7.0.0
References
CVSS V4
Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Earth Grob (Merlon Security)
Luke paris (Merlon Security)
Tijmen van der Spijk (Merlon Security)
Zohar Cochavi (Merlon Security)
Alje Woltjer (Merlon Security)
Mischa Rick van Geelen (DIVD)
Ralph Horn (DIVD)
Max van der Horst (DIVD)
Victor Pasman (DIVD)
Frank Breedijk (DIVD)
