Gbhackers PoC Exploit for Zammad Vulnerability Enables Session Hijacking and RCE
Article Content
- •CVE-2026-102489 allows session hijacking and remote code execution.
- •The vulnerability was exploited in a breach at the Dutch Institute for Vulnerability Disclosure.
- •Affected Zammad versions range from 6.3.0 to 6.5.4, with a PoC released on October 7.
A proof-of-concept (PoC) exploit for CVE-2026-102489, a vulnerability in Zammad, has been released, allowing unauthenticated attackers to steal session cookies and execute remote code. This flaw was exploited in a September breach at the Dutch Institute for Vulnerability Disclosure (DIVD), where attackers accessed systems using two zero-day vulnerabilities. The PoC, published by Horizon3.ai on October 7, details how an attacker can exploit the Zammad WebSocket endpoint to disclose sensitive session data. The vulnerability arises from improper handling of Ruby WebSocket events, leading to the exposure of connected clients' session information. Affected Zammad versions include 6.3.0 to 6.5.4. DIVD reported that the breach may have exposed volunteer-related data, including email addresses. The investigation is ongoing, and the organization has not confirmed links to known threat actors.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Dutch Institute For Vulnerability Disclosure and CVE-2026-102489 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which Zammad versions are vulnerable?
Is there confirmed exploitation in the wild?
What actions should organizations take?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Vulnerabilities in Zammad Ticketing System Under Active Exploitation Two vulnerabilities (CVE-2026-102489 and CVE-2026-102490) have been identified in the Zammad ticketing system, affecting all versions up to 7.1.3. CVE-2026-102489 allows session hijacking leading to remote code execution in versions 6.3.0 to 6.5.4, while CVE-2026-102490 enables local privilege escalation to root…