CVE-2026-102489 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 0.6% (pctl 46)
Patch first
On CISA KEV — known exploited in the wild, due 2026-10-05.
Description
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.58% — more likely to be exploited than 46% of all CVEs |
| Weakness | CWE-384 |
| On CISA KEV | yes — remediate by 2026-10-05 |
| Public exploit | none known |
| Published | 2026-09-30 |
| Last modified | 2026-10-02 |
CISA KEV
| Name | Zammad GmbH Zammad Session Fixation Vulnerability |
|---|---|
| Added | 2026-10-02 |
| Due | 2026-10-05 |
| Vendor / product | Zammad GmbH / Zammad |
| Ransomware use | none reported |
Affected (3)
| Vendor | Product |
|---|---|
| docker | docker |
| linux | linux kernel |
| zammad | zammad |
References
→ the Explorer · watch your stack · NVD