CVE-2026-102489High· 8.7▾ TwilightZammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environm…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102490High· 8.5All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
CVE-2026-84460Medium· 5.3Zammad is a web based open source helpdesk/customer support system
CVE-2026-63205Medium· 5.1Zammad is a web based open source helpdesk/customer support system
CVE-2026-63206Medium· 5.3Zammad is a web based open source helpdesk/customer support system
CVE-2026-84463Medium· 6.3Zammad is a web based open source helpdesk/customer support system
CVE-2026-63216Medium· 5.3Zammad is a web based open source helpdesk/customer support system