Zammad session hijack RCE exploited in the wild (CVE-2026-102489)
CVE-2026-102489
CVE-2026-102489: Zammad 6.3.0-6.5.4 session hijack lets unauthenticated attackers run code as the zammad user (CVSS 9.8). Update to 6.5.5 or later.
Actively exploited in the wild - CVE-2026-102489 is a critical session hijack vulnerability in Zammad versions 6.3.0 through 6.5.4 that grants unauthenticated remote code execution as the zammad user. Zammad 7.0.0 through 7.1.3 ships the same vulnerable code, but environment conditions block exploitation there.
Overview
Zammad is an open-source helpdesk and ticketing platform used by support teams to manage customer email, chat, and phone interactions. CVE-2026-102489 lets an attacker hijack a valid user session without any credentials. Once inside an authenticated session, the attacker can chain that access into arbitrary command execution on the underlying host, running with the privileges of the zammad service account.
The CVSS score is 9.8, reflecting network reachability, low attack complexity, no privileges required, and no user interaction. An attacker only needs network access to the Zammad web interface. No phishing step, no valid login, and no special configuration are required.
The 7.x branch (7.0.0 to 7.1.3) contains the same code path but is not exploitable because of environment differences in how that branch handles sessions. Treat this as a temporary reprieve, not a fix. A future release or configuration change could re-expose the flaw.
Tracked in CISA’s Known Exploited Vulnerabilities catalog, this CVE is confirmed as exploited in real attacks. The EPSS score sits at 0.6 percent, which is low, so the KEV listing, not the probability model, should drive your response.
Impact
Successful exploitation gives an attacker full control of the Zammad application context. That means:
- Reading and modifying every ticket, customer record, and internal note in the system
- Accessing stored credentials and API tokens reachable by the zammad user
- Executing arbitrary commands on the host, enabling lateral movement into the network
- Using the helpdesk as a trusted pivot for phishing customers and staff
Because Zammad often holds personally identifiable information and business correspondence, a compromise is also a data breach event. Breach reporting resources are available at breach reports, and ongoing coverage is at security news.
Remediation and Mitigation
- Upgrade Zammad to 6.5.5 or later immediately. If you run 7.0.0 through 7.1.3, upgrade to the latest 7.x release as well, since the fix is included and the environment protection is not a guarantee.
- Rotate all Zammad session secrets and API tokens after patching. Assume any session active before the upgrade may have been hijacked.
- Review Zammad and host logs for unusual ticket access, new admin accounts, or outbound connections from the zammad service account.
- Restrict network access to the Zammad web interface to trusted networks or a VPN where feasible.
- If you cannot patch immediately, take the instance offline. There is no reliable configuration workaround for a session hijack of this type.
Security Insight
Zammad is a smaller open-source project with a security team that ships fixes quickly, yet this flaw shows how session handling remains an under-audited attack surface even in mature codebases. The 7.x branch dodging exploitation by environment accident rather than design is a warning: patching based on “we’re not affected” can reverse itself without notice. Organizations running self-hosted helpdesk software should treat CVE-2026-102489 as a reminder that customer-facing support tools are high-value targets holding both data and network position.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root....
Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. The ...
Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed using...
In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind sk...