Session fixation in Zammad - CVE-2026-102489

 

Session fixation in Zammad - CVE-2026-102489

Published: October 2, 2026


Vulnerability identifier: #VU153198
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-102489
CWE-ID: CWE-384
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to session fixation issue. A remote attacker can hijack session of a high privileged user and execute arbitrary code on the system.

Note, the vulnerability is being actively exploited in the wild. 


Affected software

Zammad

How to mitigate CVE-2026-102489

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

According to DIVD, vulnerability is not exploitable in versions 7.0.0 to 7.1.3 due to environment conditions.



External References

Related Security Bulletins