A significant vulnerability in Zammad, identified as CVE-2026-102489, allows remote attackers to hijack active sessions and execute code on affected servers. This flaw, revealed through a public proof of concept (PoC), poses a severe risk to Zammad systems operating specific versions.
Affected Versions and Initial Breach
The vulnerability impacts Zammad versions 6.3.0 to 6.5.4, with later iterations up to 7.1.3 containing the same issue. However, the flaw in newer versions lacks the conditions needed for exploitation, as observed by the Dutch Institute for Vulnerability Disclosure (DIVD). The vulnerability first came to light following a breach at DIVD, where attackers reportedly exploited two zero-day vulnerabilities in Zammad.
Details of the Vulnerability
The PoC, released by Horizon3.ai, utilizes a WebSocket information leak to facilitate session hijacking and remote code execution as a low-privileged Zammad user. This exploitation method takes advantage of Zammad’s WebSocket event handling mechanism, which, when improperly handled, exposes sensitive connection data, including session cookies.
Exploitation Process and Risks
Researchers demonstrated that manipulating requests to the /ws endpoint can trigger the unintended disclosure of internal session data. These session cookies act as temporary login credentials, potentially allowing unauthorized access to authenticated sessions without traditional security checks.
The situation becomes particularly critical if an administrator’s session cookie is compromised. The PoC illustrates how an attacker can exploit this to modify the application directory, embedding malicious files and enabling remote code execution via Zammad’s package installation feature.
Call to Action for Administrators
Given the severity of the threat, administrators are urged to update Zammad to version 7 or isolate affected systems. The DIVD has provided a script to help identify signs of session cookie leaks in logs. As exploitation may have occurred before the vulnerability’s public disclosure, it is vital to preserve logs before making any system changes.
Addressing this vulnerability goes beyond patching; it requires a thorough investigation of potential past exposures to mitigate further risks effectively.
