---
id: CVE-2026-102489
title: >-
  Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability
  that leads to remote code execution as the zammad user
summary: >-
  Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability
  that leads to remote code execution as the zammad user. The vulnerability is
  also present in version 7.0.0 to version 7.1.3, but not exploitable due to
  environm…
severity: high
cvss: 8.7
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:A/AU:Y/V:C'
vendor: Zammad GmbH
product: Zammad
affected:
  - Zammad >= 6.3.0 < 6.5.4
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T19:57:08.043'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102489'
references:
  - url: 'https://csirt.divd.nl/CVE-2026-102489'
    label: csirt@divd.nl
  - url: 'https://csirt.divd.nl/DIVD-2026-00015'
    label: csirt@divd.nl
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-09-30T17:13:20.840Z'
epss: 0.00709
epssPercentile: 0.51763
---

## Overview

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
