PT-2026-103453 · Zammad · Zammad

·

CVE-2026-102489

·

Published

2026-09-30

·

Updated

2026-10-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zammad versions 6.3.0 through 6.5.4
Description A session hijack issue allows for remote code execution as the zammad user. This flaw was utilized in a real-world incident involving the DIVD Dutch Institute, where agentic AI automation was used to exfiltrate data.
Recommendations Update Zammad to version 7.0.0 or later. Take the system offline to prevent exploitation.

Fix

RCE

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102489

Affected Products

Zammad