CVE-2026-102489 PUBLISHED

Undisclosed RCE in Zammad v6.3 and higher

Assigner: DIVD
Reserved: 29.09.2026 Published: 30.09.2026 Updated: 30.09.2026

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:A/AU:Y/V:C
CVSS Score: 8.7
CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/V:C
CVSS Score: 9.4

Chained with CVE-2026-102490

Product Status

Vendor Zammad GmbH
Product Zammad
Versions Default: unaffected
  • unknown from * to 6.3.0 (excl.)
  • affected from 6.3.0 to 6.5.4 (excl.)
  • unaffected from 7.0.0 to * (excl.)

Credits

  • Earth Grob (Merlon Security) finder
  • Luke paris (Merlon Security) finder
  • Tijmen van der Spijk (Merlon Security) finder
  • Zohar Cochavi (Merlon Security) finder
  • Alje Woltjer (Merlon Security) finder
  • Mischa Rick van Geelen (DIVD) finder
  • Ralph Horn (DIVD) finder
  • Max van der Horst (DIVD) finder
  • Victor Pasman (DIVD) analyst
  • Frank Breedijk (DIVD) analyst

References