CVE-2026-102489 | Technical Details
CVE-2026-102489 is an unauthenticated session disclosure vulnerability in Zammad, an open-s 2026-10-8 18:51:44 Author: horizon3.ai(查看原文) 阅读量:7 收藏

CVE-2026-102489 is an unauthenticated session disclosure vulnerability in Zammad, an open-source helpdesk and customer support ticketing platform. An attacker can obtain connected users’ session cookies and hijack their sessions. Hijacking an administrator session can lead to remote code execution as the zammad system user. The vulnerability has been exploited in the wild and was added to CISA’s Known Exploited Vulnerabilities catalog on October 2, 2026. Horizon3’s attack research team reverse engineered the vulnerability.

Technical Details

The vulnerability affects Zammad’s WebSocket event handling. An unauthenticated attacker can send a crafted event that triggers a Ruby error. The resulting error output exposes session cookies belonging to connected users.

An attacker can replay a disclosed cookie to hijack the corresponding session. If an administrator session is exposed, that access can lead to remote code execution with the permissions of the zammad system account. Successful exploitation can expose support tickets, customer records, and credentials accessible to the application.

CVE-2026-102489 provides code execution as the zammad user. Root access requires a separate privilege escalation step. DIVD reports that attackers chained this vulnerability with CVE-2026-102490 to escalate privileges to root.

CVE-2026-102489 has a CVSS 3.x score of 9.8 (Critical)

Stop Guessing, Start Proving

CVE-2026-102489 Zammad WebSocket session disclosure vulnerability

NodeZero® Proactive Security Platform – Rapid Response

A NodeZero Rapid Response test has been developed to safely validate whether this vulnerability can be exploited in your environment. The test executes real attack techniques without causing damage, giving teams immediate clarity on exposure.

  • Run the Rapid Response test: Launch from the NodeZero platform to determine whether unauthenticated WebSocket session disclosure is possible.
  • Patch immediately: Upgrade to Zammad 7.2.0 or a later supported release, following the vendor’s update instructions.
  • Re-run the test: Confirm the vulnerability is no longer exploitable after remediation.

Indicators of Compromise

DIVD has published a log-check script for CVE-2026-102489 that searches application and web server logs for session material in error output. The script looks for error entries containing "Cookie"=>" or @clients={.

Matching entries warrant investigation for session disclosure and subsequent abuse. An absence of matches does not rule out compromise.

Affected versions & patch

Affected

DIVD’s narrative advisory identifies Zammad 6.3.0 through 6.5.4 as vulnerable. However, its structured CVE version data specifies 6.3.0 up to, but excluding, 6.5.4. Because these sources conflict, administrators should not treat 6.5.4 as a confirmed fixed release.

DIVD also reports that the vulnerable code exists in 7.0.0 through 7.1.3, but is not exploitable because of the runtime environment. Zammad states that 7.0 and later are not affected in practice.

Fixed

Upgrade to Zammad 7.2.0 or a later supported release. Zammad confirms that 7.2.0 includes hardening of the affected code and recommends this upgrade for administrators. Versions 6.5 and earlier are no longer supported and do not receive security fixes.

Mitigations

DIVD recommends upgrading to version 7 or taking the instance offline. Its advisory does not list a workaround.

Timeline

  • September 24, 2026: DIVD reported the vulnerability to Zammad.
  • September 26, 2026: DIVD issued a limited disclosure, scanned public instances, and began notifying owners.
  • September 30, 2026: Publication date of the central CVE record. DIVD’s own advisory separately lists September 29.
  • October 1, 2026: Zammad published its statement and recommended 7.2.0.
  • October 2, 2026: CISA added CVE-2026-102489 to its Known Exploited Vulnerabilities catalog.
  • October XX, 2026: Horizon3 alerted affected Rapid Response customers and released the NodeZero Rapid Response test for CVE-2026-102489

References


文章来源: https://horizon3.ai/attack-research/vulnerabilities/cve-2026-102489/
如有侵权请联系:admin#unsafe.sh