peter bassill · operator
$ cve CVE-2026-102489 JSON

CVE-2026-102489 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 0.6% (pctl 46)

Patch first

On CISA KEV — known exploited in the wild, due 2026-10-05.

Description

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.58% — more likely to be exploited than 46% of all CVEs
WeaknessCWE-384
On CISA KEVyes — remediate by 2026-10-05
Public exploitnone known
Published2026-09-30
Last modified2026-10-02

CISA KEV

NameZammad GmbH Zammad Session Fixation Vulnerability
Added2026-10-02
Due2026-10-05
Vendor / productZammad GmbH / Zammad
Ransomware usenone reported

Affected (3)

VendorProduct
dockerdocker
linuxlinux kernel
zammadzammad

References

→ the Explorer  ·  watch your stack  ·  NVD