Skip to content
PoC Exploit for Zammad Vulnerability Enables Session Hijacking and RCE

PoC Exploit for Zammad Vulnerability Enables Session Hijacking and RCE

First seen 8 Oct 2026, 16:41 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 17:35 UTC

A proof-of-concept (PoC) exploit for CVE-2026-102489, a vulnerability in Zammad, has been released, allowing unauthenticated attackers to steal session cookies and execute remote code. This flaw was exploited in a September breach at the Dutch Institute for Vulnerability Disclosure (DIVD), where attackers accessed systems using two zero-day vulnerabilities. The PoC, published by Horizon3.ai on October 7, details how an attacker can exploit the Zammad WebSocket endpoint to disclose sensitive session data. The vulnerability arises from improper handling of Ruby WebSocket events, leading to the exposure of connected clients' session information. Affected Zammad versions include 6.3.0 to 6.5.4. DIVD reported that the breach may have exposed volunteer-related data, including email addresses. The investigation is ongoing, and the organization has not confirmed links to known threat actors.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-21
Initial access to DIVD systems
Attackers reportedly accessed DIVD's systems exploiting Zammad vulnerabilities.
Gbhackers
2026-09-30
CVE-2026-102489 published
CVE-2026-102489 was published, highlighting its critical nature and exploitation potential.
Gbhackers
2026-09-30
CVE-2026-102490 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-02
CVE added to CISA KEV
CISA added CVE-2026-102489 to its Known Exploited Vulnerabilities catalog.
Gbhackers
2026-10-07
Public PoC released
Horizon3.ai published a PoC for CVE-2026-102489, detailing exploitation methods.
Gbhackers

More articles in this cluster (2)

Following this threat?

Track Dutch Institute For Vulnerability Disclosure and CVE-2026-102489 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which Zammad versions are vulnerable?
Zammad versions 6.3.0 through 6.5.4 are affected by CVE-2026-102489.
Is there confirmed exploitation in the wild?
Yes, the vulnerability has been actively exploited, as evidenced by the breach at DIVD.
What actions should organizations take?
Organizations should immediately assess their Zammad versions and apply any available patches or mitigations.