Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Zammad Flaw Allows Remote Code Execution via Session Leak

Zammad Flaw Allows Remote Code Execution via Session Leak

Posted on October 8, 2026 By CWS

A significant vulnerability in Zammad, identified as CVE-2026-102489, allows remote attackers to hijack active sessions and execute code on affected servers. This flaw, revealed through a public proof of concept (PoC), poses a severe risk to Zammad systems operating specific versions.

Affected Versions and Initial Breach

The vulnerability impacts Zammad versions 6.3.0 to 6.5.4, with later iterations up to 7.1.3 containing the same issue. However, the flaw in newer versions lacks the conditions needed for exploitation, as observed by the Dutch Institute for Vulnerability Disclosure (DIVD). The vulnerability first came to light following a breach at DIVD, where attackers reportedly exploited two zero-day vulnerabilities in Zammad.

Details of the Vulnerability

The PoC, released by Horizon3.ai, utilizes a WebSocket information leak to facilitate session hijacking and remote code execution as a low-privileged Zammad user. This exploitation method takes advantage of Zammad’s WebSocket event handling mechanism, which, when improperly handled, exposes sensitive connection data, including session cookies.

Exploitation Process and Risks

Researchers demonstrated that manipulating requests to the /ws endpoint can trigger the unintended disclosure of internal session data. These session cookies act as temporary login credentials, potentially allowing unauthorized access to authenticated sessions without traditional security checks.

The situation becomes particularly critical if an administrator’s session cookie is compromised. The PoC illustrates how an attacker can exploit this to modify the application directory, embedding malicious files and enabling remote code execution via Zammad’s package installation feature.

Call to Action for Administrators

Given the severity of the threat, administrators are urged to update Zammad to version 7 or isolate affected systems. The DIVD has provided a script to help identify signs of session cookie leaks in logs. As exploitation may have occurred before the vulnerability’s public disclosure, it is vital to preserve logs before making any system changes.

Addressing this vulnerability goes beyond patching; it requires a thorough investigation of potential past exposures to mitigate further risks effectively.

Cyber Security News Tags:CVE-2026-102489, Cybersecurity, DIVD, Horizon3.ai, PoC, remote code execution, session leak, Vulnerability, WebSocket, Zammad

Post navigation

Previous Post: Hackers Exploit Atlassian Vulnerability Soon After Disclosure
Next Post: Japan Faces Surge in Data Breaches Due to API and Software Vulnerabilities

Related Posts

Stryker Faces Major Cyberattack by Iran-Linked Group Stryker Faces Major Cyberattack by Iran-Linked Group Cyber Security News
North Korean Kimsuky Hackers Data Breach North Korean Kimsuky Hackers Data Breach Cyber Security News
Attackers Can Exploit WerFaultSecure.exe Tool to Steal Cached Passwords From Windows 11 24H2 Attackers Can Exploit WerFaultSecure.exe Tool to Steal Cached Passwords From Windows 11 24H2 Cyber Security News
Elite Cyber Veterans Launch Blast Security with M to Turn Cloud Detection into Prevention Elite Cyber Veterans Launch Blast Security with $10M to Turn Cloud Detection into Prevention Cyber Security News
Threat Actors Exploiting Black Friday Shopping Hype Threat Actors Exploiting Black Friday Shopping Hype Cyber Security News
Mozilla Wants All New Firefox Extensions to Disclose Data Collection Policies Mozilla Wants All New Firefox Extensions to Disclose Data Collection Policies Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • VirusTotal API Keys Allegedly Sold on Dark Web
  • Fortinet Devices Targeted by FortiBleed Attackers
  • Japan Faces Surge in Data Breaches Due to API and Software Vulnerabilities
  • Zammad Flaw Allows Remote Code Execution via Session Leak
  • Hackers Exploit Atlassian Vulnerability Soon After Disclosure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • VirusTotal API Keys Allegedly Sold on Dark Web
  • Fortinet Devices Targeted by FortiBleed Attackers
  • Japan Faces Surge in Data Breaches Due to API and Software Vulnerabilities
  • Zammad Flaw Allows Remote Code Execution via Session Leak
  • Hackers Exploit Atlassian Vulnerability Soon After Disclosure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark