## Overview
CISA added CVE-2026-102489 to its Known Exploited Vulnerabilities (KEV) catalog on October 2, 2026. This session fixation vulnerability affects Zammad versions 6.3.0 through 6.5.4. It allows attackers to hijack sessions and execute remote code as the zammad user. The vulnerability also exists in versions 7.0.0 to 7.1.3, but it is not currently exploitable due to specific environmental conditions.
## Technical Details
The vulnerability arises from improper handling of session identifiers, which allows attackers to fixate a session. By manipulating the session, an attacker can gain unauthorized access to the application. This flaw can be chained with CVE-2026-102490 to escalate privileges further. The CVSS score of 9.4 indicates a critical risk level, highlighting the potential for severe impact if exploited.
## Impact
Successful exploitation of CVE-2026-102489 can lead to remote code execution, allowing attackers to execute arbitrary commands on the server as the zammad user. This could result in data breaches, unauthorized access to sensitive information, and potential system compromise. The addition to the CISA KEV list signals a heightened risk of exploitation, especially as evidence of active exploitation emerges.
## Mitigation
Defenders should immediately update Zammad to the latest version to mitigate this vulnerability. For those using affected versions, it is crucial to monitor for unusual activity and consider implementing additional security measures, such as web application firewalls and intrusion detection systems. Regularly review and apply security patches to maintain a secure environment.
CSURFACE Threat Sensor