CVE-2026-102489

CRITICAL CISA KEV Pub 30/09 Upd 03/10

Overview

This vulnerability is a session hijacking flaw rooted in improper session management within Zammad's authentication mechanism. The affected component fails to adequately validate or isolate session tokens, allowing unauthorized users to assume the identity of legitimate sessions. The flaw exists in the session handling logic of Zammad versions 6.3.0 through 6.5.4 and partially in versions 7.0.0 to 7.1.3 under specific environmental conditions.

Vulnerability Description

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

Impact

An attacker without prior authentication or user interaction can hijack active sessions, gaining unauthorized access to the Zammad application as the legitimate user. This access enables execution of arbitrary commands with the privileges of the 'zammad' user, potentially leading to full system compromise. The vulnerability facilitates lateral movement within the affected environment and unauthorized data access or manipulation, resulting in severe business impact including data breaches and operational disruption.

Solution

Users of Zammad versions 6.3.0 through 6.5.4 should upgrade to versions later than 6.5.4. For versions 7.0.0 through 7.1.3, ensure environment configurations mitigate exploitability or upgrade beyond 7.1.3. Refer to the DIVD advisory DIVD-2026-00015 for detailed patching instructions and vendor recommendations available at https://csirt.divd.nl/DIVD-2026-00015. No specific workarounds are provided; applying vendor patches is the primary remediation step.

EPSS vs KEV Prediction — Evolution (30 days)

Affected Products (2)

Vendor Product Version CPE
zammad Zammad Zammad All cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*
zammad Zammad Zammad All cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*

Exploits

No exploits found for this CVE.

Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest VERY HIGH
Sightings Extensive activity

Threat Feed

6 events
2026-10-03
Threat Sensor Sighting — Extensive activity

Sighting activity recorded

2026-10-02
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-10-02
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

2026-10-01
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-09-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

Detected as Exploited in the Wild (516 sightings)

Active exploitation confirmed with 516 sighting(s)

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.

Attack Vectors ML

Remote Code Execution
88% rce
Session Fixation
85% session_fixation
Code Injection
66% code_injection
OS Command Injection
48% command_injection

MITRE ATT&CK Techniques (0)

ATT&CK techniques pending

Techniques are derived from this CVE's kill chains once ML classification completes.

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-31 Accessing/Intercepting/Modifying HTTP Cookies
70%
High High
CAPEC-21 Exploitation of Trusted Identifiers
43%
High High
CAPEC-196 Session Credential Falsification through Forging
30%
Medium Medium
CAPEC-39 Manipulating Opaque Client-based Data Tokens
30%
High Medium
CAPEC-59 Session Credential Falsification through Prediction
30%
High High

Red Team Playbook

AtomicRedTeam integration in progress

Executable commands will be auto-mapped to each ATT&CK technique of this CVE.

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (4)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2026-102489
csirt.divd.nl
GitHub CVE third-party-advisory
https://csirt.divd.nl/DIVD-2026-00015
csirt.divd.nl
GitHub CVE third-party-advisory
https://csirt.divd.nl/CVE-2026-102489
cisa.gov
NVD API US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-102489