Skip to content

CVE-2026-102489

Zammad session hijack to remote code execution listed in CISA KEV (CVE-2026-102489)

Critical 9.4 KEV Published

Zammad 6.3.0 to before 6.5.4 has a session hijack vulnerability leading to remote code execution as the zammad user (CVSS 9.4). CISA KEV lists it as exploited with a due date of 5 October 2026. Upgrade to Zammad 6.5.4.

What happened

The CVE record describes a session hijack that can be turned into remote code execution under the account used by the Zammad application. The CVSS 4.0 vector rates it critical at 9.4: it is reachable over the network, has low attack complexity, requires no prior privileges, and needs only passive user interaction. Successful exploitation gives an attacker high impact on confidentiality, integrity and availability of the vulnerable system, as well as high impact on subsequent systems.

CISA's KEV entry added CVE-2026-102489 on 2 October 2026 and lists it as exploited. CISA's required action is to apply mitigations in accordance with vendor instructions, follow applicable BOD 26-04 guidance, and discontinue use of the product if mitigations are unavailable. The CVE record does not state that public exploit details are available.

Who is affected

The affected product is Zammad. The CVE description states that versions 6.3.0 to 6.5.4 are vulnerable; the affected range shown alongside the fix is 6.3.0 to before 6.5.4, with 6.5.4 as the fixed release. The description also says the issue is present in 7.0.0 to 7.1.3 but is not exploitable there because of environment conditions. Because the vulnerability is reachable over the network, a Zammad instance exposed to the internet or to untrusted users should be treated as relevant until the exact version is confirmed.

What to do now

  1. Upgrade to Zammad 6.5.4, the fixed version listed in the CVE record.
  2. If the instance cannot be upgraded immediately, restrict network access to the Zammad service until the upgrade is possible. No workaround has been published.
  3. Follow CISA's KEV required action for CVE-2026-102489: evaluate each asset's internet exposure, apply BOD 26-04 patching guidelines, and discontinue use of the product if mitigation is unavailable. CISA's due date is 5 October 2026.

How to detect it

No vendor indicators of compromise are listed. Because the flaw is a session hijack leading to remote code execution under the zammad account, review sessions for unexpected sources or activity, and look for processes or commands appearing under the zammad account that cannot be explained by normal maintenance.

Beyond the patch

The practical pressure here is not only the patch deadline: CISA's KEV entry says the vulnerability is actively exploited, so an affected Zammad instance may already have been reached. Managed Detection & Response (MDR) fits because detection and response are the first line once a KEV-listed exploit is in play, and Virtual CISO Services (vCISO) can help check whether exposed services such as Zammad are reachable from the internet and how to reduce that exposure. Book a meeting if you need to discuss an urgent response.

Affected and fixed versions

ProductAffectedFixed in
Zammad6.3.0 – < 6.5.46.5.4

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.