PT-2026-103453 · Zammad · Zammad
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zammad versions 6.3.0 through 6.5.4
Description
A session hijack issue allows for remote code execution as the zammad user. This flaw was utilized in a real-world incident involving the DIVD Dutch Institute, where agentic AI automation was used to exfiltrate data.
Recommendations
Update Zammad to version 7.0.0 or later.
Take the system offline to prevent exploitation.
Fix
RCE
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zammad