CVE-2026-102489
Overview
This vulnerability is a session hijacking flaw rooted in improper session management within Zammad's authentication mechanism. The affected component fails to adequately validate or isolate session tokens, allowing unauthorized users to assume the identity of legitimate sessions. The flaw exists in the session handling logic of Zammad versions 6.3.0 through 6.5.4 and partially in versions 7.0.0 to 7.1.3 under specific environmental conditions.
Vulnerability Description
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
Impact
An attacker without prior authentication or user interaction can hijack active sessions, gaining unauthorized access to the Zammad application as the legitimate user. This access enables execution of arbitrary commands with the privileges of the 'zammad' user, potentially leading to full system compromise. The vulnerability facilitates lateral movement within the affected environment and unauthorized data access or manipulation, resulting in severe business impact including data breaches and operational disruption.
Solution
Users of Zammad versions 6.3.0 through 6.5.4 should upgrade to versions later than 6.5.4. For versions 7.0.0 through 7.1.3, ensure environment configurations mitigate exploitability or upgrade beyond 7.1.3. Refer to the DIVD advisory DIVD-2026-00015 for detailed patching instructions and vendor recommendations available at https://csirt.divd.nl/DIVD-2026-00015. No specific workarounds are provided; applying vendor patches is the primary remediation step.
EPSS vs KEV Prediction — Evolution (30 days)
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Zammad | Zammad | All |
cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*
|
|
|
Zammad | Zammad | All |
cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
6 eventsSighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Sighting activity recorded
Sighting activity recorded
Active exploitation confirmed with 516 sighting(s)
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.
Attack Vectors ML
MITRE ATT&CK Techniques (0)
Techniques are derived from this CVE's kill chains once ML classification completes.
CAPEC Attack Patterns ML
Red Team Playbook
Executable commands will be auto-mapped to each ATT&CK technique of this CVE.
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2026-102489 |
| csirt.divd.nl |
GitHub CVE
third-party-advisory
|
https://csirt.divd.nl/DIVD-2026-00015 |
| csirt.divd.nl |
GitHub CVE
third-party-advisory
|
https://csirt.divd.nl/CVE-2026-102489 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-102489 |