Zammad security alert: session hijacking and remote code execution CVE-2026-102489

in #secpoint • 3 days ago

Zammad security alert: session hijacking and remote code execution

CVE-2026-102489 concerns session hijacking that can lead to code execution as the Zammad service account on affected older installations. DIVD reports exploitation in a real incident.

Zammad states that version 7.0 and later are not exploitable through this issue and recommends upgrading to 7.2.0.

SecPoint Penetrator includes an assessment for CVE-2026-102489 to help identify potentially affected systems and prioritize upgrades.

Review exposed helpdesk systems and investigate signs of compromise.

#Zammad #CyberSecurity #VulnerabilityManagement #SecPoint #Penetrator
secpoint-zammad.png