CRITICAL 9.4 NVD

CVE-2026-102489

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also p

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

References

Published: 2026-09-30 · Source: NVD · Feed updated: 2026-09-30
This critical severity vulnerability with a CVSS score of 9.4 was published on 2026-09-30 via NVD.

Risk Timeline

CVE Disclosed2026-09-30 · -1 days ago

Remediation Resources

vulnfeed aggregates 9504 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.