high Known exploited

CVE-2026-102489

Zammad GmbH Zammad Session Fixation Vulnerability

Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.

Published
Sep 30, 2026
Vendor
Zammad GmbH
Product
Zammad
CISA due date
2026-10-05
Source
merged

References

Check your website: Korisec scans for exposed services, weak TLS, missing headers, and WordPress plugin risks. Run a free scan or start a trial.

← Back to CVE Tracker · Official record: cve.org