CVE-2026-102489: Undisclosed RCE in Zammad v6.3 and higher
Published Sep 30, 2026
·Updated
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
Affected Software
1 affected component
Zammad Zammad>=6.3.0<=6.5.4, >=7.0.0<=7.1.3
Event History
Sep 30, 2026
CVE Published
via MITRE·04:21 PM
Data Sourced
via MITRE·04:21 PM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverity
Frequently Asked Questions
1
Which deployments are practically exploitable?
Zammad versions 6.3.0 through 6.5.4 are described as vulnerable to session hijacking that can lead to remote code execution as the zammad user. Versions 7.0.0 through 7.1.3 are also affected, but the issue is not exploitable there because of environmental conditions.
2
What level of access could an attacker gain?
Successful exploitation can result in remote code execution with the privileges of the zammad user.