CriticalCritical vulnerability
CVE-2026-102489 (CVSS 9.4)
NVD · officialPublished Sep 30, 2026Risk 50/100
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
Technical details
CVSS
9.4
AV:NetworkAC:LowPR:NoneUI:Passive
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source