Session fixation in Zammad - CVE-2026-102489
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to session fixation issue. A remote attacker can hijack session of a high privileged user and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2026-102489
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
According to DIVD, vulnerability is not exploitable in versions 7.0.0 to 7.1.3 due to environment conditions.