OCTOBER 2, 2026
Live Feed
Back to database
Case File

CVE-2026-102489

CRITICAL · CVSS 9.8 EPSS 0.58% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-02

CyberRota Analysis

AI-Generated

Zammad versions 6.3.0 to 6.5.4 are susceptible to a session hijacking vulnerability that allows remote code execution as the zammad user. While versions 7.0.0 to 7.1.3 contain the vulnerability, it is not exploitable under current environmental conditions. Organizations using affected versions should prioritize immediate remediation to mitigate the risk of unauthorized access and potential system compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102489
Severity
CRITICAL
CVSS
9.8
EPSS
0.58%

Original NVD Description

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

Related CVEs

Other vulnerabilities affecting the same vendor(s)