Back Gbhackers PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489 , a critical vulnerability in Zammad that can expose active users’ session cookies and enable remote code execution (RCE) as the Zammad operating system user.
This flaw was reportedly exploited during the September breach of the Dutch Institute for Vulnerability Disclosure (DIVD), alongside a separate local privilege escalation issue tracked as CVE-2026-102490.
Horizon3.ai’s Attack Team published technical details and exploit code on October 7, revealing that an unauthenticated attacker can send a crafted message to Zammad’s WebSocket endpoint (/ws).
This malformed event triggers an application error, causing the response to include the internal state of connected clients, such as HTTP Cookie headers and valid _zammad_session values.
The vulnerability originates from how Zammad handles Ruby WebSocket events. The application maintains connected-client data in a global @clients object, which includes request headers.
When the provided event name resolves to `Sessions::Event::Base`, Zammad attempts to instantiate the class using the client registry. However, the base handler does not implement the expected `run()` method, resulting in a Ruby NoMethodError.
Instead of returning a sanitized failure response, the vulnerable code returns an error string that includes the object representation, revealing instance variables and the @clients registry. As a result, an attacker can disclose session data from active connected users.
For the public PoC to work, at least one authenticated user must be connected to the WebSocket service during the exploitation. An attacker then needs to identify a usable privileged session cookie, ideally one associated with an administrator account, to further their attack.
According to Horizon3.ai, if an attacker hijacks an administrator session, they can exploit Zammad’s package-installation functionality to write attacker-controlled files into the application directory. The PoC reportedly installs a malicious ERB template that replaces the built-in password reset email view.
DIVD reported that attackers first accessed its systems on September 21, and detected malicious activity the following day. They attributed the initial access to two previously unknown Zammad vulnerabilities : CVE-2026-102489, which allows session hijacking and RCE, and CVE-2026-102490, which elevates privileges from the Zammad user to root.
DIVD characterized the intrusion as an alleged “agentic AI-powered attack,” citing forensic artifacts and attacker scripts. However, their investigation is ongoing, and they have not yet established a connection to any known public threat actor.
Network segmentation and incident-response actions limited further movement. However, the organization confirmed that volunteer-related data, including email addresses and possibly information, may have been exposed.
DIVD lists Zammad versions 6.3.0 through 6.5.4 as vulnerable to the session hijack-to-RCE chain. Versions 7.0.0 through 7.1.3 reportedly contain the flaw but are not exploitable under the environmental conditions DIVD identified. CVE-2026-102490 affects Zammad versions 1.5.0 through 7.1.0-alpha and enables local privilege escalation.
The release of functional exploit code underscores the urgency for defenders: an unauthenticated disclosure bug can quickly become a direct RCE pathway when an active privileged session is available.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC .
Artificial Intelligence
Cyber security Course
Cyber Security Resources
Cybersecurity
Information Gathering
Information Security Risks
Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware
Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available
16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys
Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones
wolfSSH Patches 5 Security Vulnerabilities, Including Critical SSH Authentication Bypass
Critical Gitea Vulnerabilities Allow Attackers to Bypass Authentication and Execute Code
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
