← back
CVE-2026-102489highobserved exploitation

Undisclosed RCE in Zammad v6.3 and higher

43Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 8.7epss 0.7%
from disclosure to weapon
Published on NVDSep 30
VulnCheckSep 30
exploitation probability
0.7%top 48% of all CVEs
observed exploitation
yesVulnCheck
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:A/AU:Y/V:C
Affected products
Zammad GmbH · Zammad