type: cve · created: 2026-10-01 · updated: 2026-10-01 · tags: [cve, rce, zammad, session-hijacking, active-exploitation] · confidence: high · severity: critical · affected_sectors: [global, technology] · au_impact: false
Zammad versions 6.3.0 to 6.5.4 are vulnerable to a session hijacking flaw that leads to remote code execution as the zammad user. The flaw is also present in versions 7.0.0 to 7.1.3 but is not exploitable there because of environment conditions. The Dutch Institute for Vulnerability Disclosure (DIVD) found it in collaboration with Merlon Security and named it publicly on 30 September 2026 as one of two zero-days chained in the breach of DIVD's own network, where the pair together enabled session hijacking, remote code execution and a jump to root "in seconds" under agentic control. DIVD recommends upgrading to Zammad version 7 or taking instances offline.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-102489 |
| CVSS | 9.4 (Critical) — CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
| Vendor / product | Zammad — open-source helpdesk and ticketing platform |
| Reported | 2026-09-30 |