← Back to CVE List
CVE-2026-102489NVD
Vulnerability Summary
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
CVSS v4.0 Base Metrics — Score 8.7 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionPassive
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)High
Confidentiality (Subsequent System)Low
Integrity (Subsequent System)Low
Availability (Subsequent System)Low
Affected & Patched Versions
- Zammad GmbH Zammad >= * and < 6.3.0
- Zammad GmbH Zammad >= 6.3.0 and < 6.5.4
- Zammad GmbH Zammad 6.3.0
- Zammad GmbH Zammad 6.5.4