🔴 CVE-2026-102489

CVE-2026-102489 is an actively exploited session hijack vulnerability in Zammad helpdesk (versions 6.3.0–6.5.4) that leads to remote code execution as the 'zammad' system user. Zammad is a web-based customer support platform routinely exposed to the internet, making this a direct T1190 threat. The vulnerability is confirmed in CISA KEV and has been weaponised in real-world attack campaigns, including one that targeted DIVD itself, chained with CVE-2026-102490 to achieve full root-level compromise.

← Back to Overview
HIGH_RISK
Risk Level
8.7
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-09-30

Added to CISA KEV: 2026-10-02 2 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-10-02)

Summary

CVE-2026-102489 is a critical session hijacking vulnerability affecting the Zammad helpdesk platform, specifically versions 6.3.0 through 6.5.4. The flaw originates from inadequate protection of session tokens, which allows an attacker to hijack active user sessions. By successfully exploiting this vulnerability, an unauthorized party can execute arbitrary commands as the dedicated `zammad` system user, making it a high-severity issue that threatens the integrity and confidentiality of the entire helpdesk environment [1][3].

Exploitation

  • Active Exploitation: The vulnerability has been confirmed as actively exploited in the wild and is listed in the CISA Known Exploited Vulnerabilities (KEV) Catalog [5].
  • Threat Actors/Campaigns: It has been linked to AI-driven network breaches, notably in attacks targeting the Dutch Institute for Vulnerability Disclosure (DIVD), where it was chained with another zero-day (CVE-2026-102490) to escalate privileges to root [2][4].
  • Proof-of-Concept: While the vulnerability is being actively exploited in sophisticated campaigns, public-facing, simplified proof-of-concept exploit tools are increasingly associated with such high-profile zero-days post-disclosure [2].
  • Attack Prerequisites: The exploit is considered network-based and can be leveraged by unauthenticated or low-privilege attackers to inject malicious commands by targeting session management weaknesses [1].

Affected Products & Patches

  • Affected Versions: Zammad versions 6.3.0 through 6.5.4 are confirmed to be vulnerable [3].
  • Patch Status: Organizations are advised to check the official Zammad vendor security advisories for the latest patched versions that remediate these session management flaws.
  • Mitigations: In environments where patching is not immediately feasible, network-level restrictions limiting access to the Zammad instance and monitoring for suspicious session token activity are recommended as temporary mitigations.

Impact

  • Access/Capabilities: Successful exploitation grants the attacker the ability to hijack user sessions and subsequently execute arbitrary code within the context of the `zammad` system user [1].
  • Business Risk: For internet-facing deployments, this vulnerability poses a severe risk, as it can lead to full system compromise, lateral movement into internal networks, and the exfiltration of sensitive data such as customer contact details and internal communications [2][4].

Sources

  1. CVE-2026-102489 - Vulnerability Details - OpenCVE

    A session hijack flaw in Zammad allows an attacker to take control of a user session and execute arbitrary code as the dedicated zammad system user. The vulnerability originates from inadequate protection of session tokens, enabling an unauthenticated or low‑privilege attacker to inject malicious co…

  2. CVE-2026-102489 - Exploits & Severity - Feedly

    The intruders chained two zero-days in the Zammad helpdesk platform, CVE-2026-102489 and CVE-2026-102490, to hijack sessions, execute code remotely and escalate to root within seconds before moving to other services and exfiltrating data, including volunteer email addresses and possibly contact deta…

  3. NVD-CVE-2026-102489

    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The ...

  4. DIVD says Zammad zero-days enabled AI-driven network breach

    According to the cybersecurity nonprofit, the two flaws, now identified as CVE-2026-102489 and CVE-2026-102490, enabled session hijacking, remote code execution, and escalation to root privileges.

  5. CISA Adds Four Known Exploited Vulnerabilities to Catalog

    CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.