CVE-2026-102489
Last modified
CVE-2026-102489 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.. CISA has confirmed active exploitation in the wild. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zammad | Zammad | >= 6.3.0, < 6.5.4 |
| Zammad | Zammad | >= 7.0.0, <= 7.1.3 |
References
- https://csirt.divd.nl/CVE-2026-102489Third Party Advisory
- https://csirt.divd.nl/DIVD-2026-00015Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-102489US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-102489?
How severe is CVE-2026-102489?
How do I fix CVE-2026-102489?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-102459EasyFlow .NET developed by Digiwin has a Reflected Cross-sit…6.1
- CVE-2026-10246A vulnerability has been found in SourceCodester Pharmacy Sa…3.5
- CVE-2026-10247A vulnerability was found in SourceCodester Pharmacy Sales a…3.5
- CVE-2026-102473A flaw was found in dash. When built without libc fnmatch, t…5.5
- CVE-2026-102474A flaw was found in dash. The printf builtin reserves four b…4
- CVE-2026-10248A vulnerability was determined in SourceCodester Pharmacy Sa…4.7
- CVE-2026-10249A vulnerability was identified in itsourcecode Online Blood …7.3
- CVE-2026-102490All versions of Zammad including the latest alpha enable the…9.8
- CVE-2026-102491A vulnerability was identified in mahonelau kykms up to 8f13…7.3
- CVE-2026-102495Apache XmlSchema doesn't limit how deeply schema imports and…7.5
- CVE-2026-102496Apache XmlSchema doesn't limit how deeply schema structures …7.5
- CVE-2026-102497The Apache XmlSchema walker (xmlschema-walker) doesn't detec…7.5
Are you affected by CVE-2026-102489?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
