External risk intelligence

Zammad Session Hijack Vulnerability Allows Remote Code Execution.

CVE advisoryKnown Exploit

CVE-2026-102489

Zammad is an open-source helpdesk and ticketing system. By design, such systems are typically deployed as public-facing web applications to enable user support, customer communication, and ticket submission via the internet, making them inherently internet-exposed services.

Remote Code Execution

Zammad

6.3.0 to before 6.5.47.0.0 to 7.1.3

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security vulnerability has been identified in Zammad, a helpdesk and ticketing system, potentially allowing unauthorized access and remote code execution. While certain versions are more susceptible, the primary concern is confirming if our environment utilizes the affected technology.

  • Session hijacking risk in helpdesk software.
  • Matters if Zammad is in use.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker could potentially hijack a user's session in Zammad to execute remote code. This attack begins with an attacker finding an exposed Zammad instance and then tricking a user into interacting with a malicious link. This interaction allows the attacker to take over the user's active session, leading to unauthorized actions as that user.

  • Requires no authentication or privileges.
  • Triggered by user interaction with a malicious link.
  • Leads to remote code execution.

Live Threat

Current exploitation, exposure, and threat context

In Zammad versions 6.3.0 to 6.5.4, a session hijack vulnerability could allow an attacker to execute arbitrary code as the zammad user, impacting the integrity and availability of the system. This vulnerability is present but not exploitable in versions 7.0.0 to 7.1.3 due to specific environmental conditions.

  • System data and service integrity could be compromised.
  • Exploitation may occur through specially crafted network requests.
  • Unauthorized remote code execution could disrupt services.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and platform teams are likely responsible for addressing this vulnerability within their Zammad deployments. The immediate first step is to inventory all instances of the affected software, assess their internet exposure and business criticality, and identify the accountable system owner. This information will inform the prioritization and planning of remediation efforts.

  • Application owners should manage the remediation.
  • Verify internet exposure and business criticality.
  • Plan and execute updates during maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Zammad?

Zammad is an open-source helpdesk and customer support ticketing system. Organizations use it to manage communications, track user requests, and organize support workflows. Because it functions as a web-based service, it is often configured to be accessible over the internet to allow customers and support agents to interact with the platform seamlessly from different locations.

What does CVE-2026-102489 mean for system security?

This vulnerability is classified as CWE-384, or session fixation. In the context of CVE-2026-102489, it means an attacker can potentially hijack an active user's session within the Zammad application. If successful, this flaw allows the attacker to gain unauthorized access and execute remote code as the Zammad user, giving them significant control over the software's operations and the data it handles.

How is this Zammad vulnerability triggered?

An attacker typically triggers this by tricking a legitimate user into interacting with a malicious link while they are accessing the Zammad instance. It is important to note that while the vulnerability exists in versions 7.0.0 through 7.1.3, it is not exploitable there due to specific environmental conditions. Exploitation specifically targets the session handling mechanism, which requires this user interaction to succeed.

How do I know if my Zammad instance is at risk?

You should consider the environment's reachability. According to Halo Surface Signal, Zammad is frequently deployed as a public-facing web application to facilitate support services, which makes many instances inherently exposed to the internet. If your installation is internet-facing, it falls under a higher priority for review, whereas internal-only instances may have a different risk profile depending on your network segmentation.

What should I do first if I run Zammad?

The immediate first step is to perform a comprehensive inventory of all Zammad instances within your environment. Once you have a complete list, verify the specific version number for each deployment to determine if it falls within the affected ranges. After identifying your assets, coordinate with your system and application owners to assess the business criticality of each instance and prepare for necessary updates or mitigation measures.

References