CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-10-02. EPSS: 1.3% chance of exploitation in the next 30 days.

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The bug is also present in version 7.0.0 to version 7.1.2, but not exploitable due to changes in the underlying framework.

Affected products

  • Zammad Zammad: from 6.3.0, up to and including 6.5.4

Published 2026-09-30. Last modified 2026-10-10.