CVE-2026-102489 is an actively exploited session hijack vulnerability in Zammad helpdesk (versions 6.3.0–6.5.4) that leads to remote code execution as the 'zammad' system user. Zammad is a web-based customer support platform routinely exposed to the internet, making this a direct T1190 threat. The vulnerability is confirmed in CISA KEV and has been weaponised in real-world attack campaigns, including one that targeted DIVD itself, chained with CVE-2026-102490 to achieve full root-level compromise.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-09-30
Added to CISA KEV: 2026-10-02 2 DAYS BETWEEN CVE AND KEV
CVE-2026-102489 is a critical session hijacking vulnerability affecting the Zammad helpdesk platform, specifically versions 6.3.0 through 6.5.4. The flaw originates from inadequate protection of session tokens, which allows an attacker to hijack active user sessions. By successfully exploiting this vulnerability, an unauthorized party can execute arbitrary commands as the dedicated `zammad` system user, making it a high-severity issue that threatens the integrity and confidentiality of the entire helpdesk environment [1][3].
A session hijack flaw in Zammad allows an attacker to take control of a user session and execute arbitrary code as the dedicated zammad system user. The vulnerability originates from inadequate protection of session tokens, enabling an unauthenticated or low‑privilege attacker to inject malicious co…
The intruders chained two zero-days in the Zammad helpdesk platform, CVE-2026-102489 and CVE-2026-102490, to hijack sessions, execute code remotely and escalate to root within seconds before moving to other services and exfiltrating data, including volunteer email addresses and possibly contact deta…
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The ...
According to the cybersecurity nonprofit, the two flaws, now identified as CVE-2026-102489 and CVE-2026-102490, enabled session hijacking, remote code execution, and escalation to root privileges.
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.