Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Zammad Flaw Allows Remote Code Execution via Session Leak

Zammad Flaw Allows Remote Code Execution via Session Leak

Posted on October 8, 2026 By CWS

A significant vulnerability in Zammad, identified as CVE-2026-102489, allows remote attackers to hijack active sessions and execute code on affected servers. This flaw, revealed through a public proof of concept (PoC), poses a severe risk to Zammad systems operating specific versions.

Affected Versions and Initial Breach

The vulnerability impacts Zammad versions 6.3.0 to 6.5.4, with later iterations up to 7.1.3 containing the same issue. However, the flaw in newer versions lacks the conditions needed for exploitation, as observed by the Dutch Institute for Vulnerability Disclosure (DIVD). The vulnerability first came to light following a breach at DIVD, where attackers reportedly exploited two zero-day vulnerabilities in Zammad.

Details of the Vulnerability

The PoC, released by Horizon3.ai, utilizes a WebSocket information leak to facilitate session hijacking and remote code execution as a low-privileged Zammad user. This exploitation method takes advantage of Zammad’s WebSocket event handling mechanism, which, when improperly handled, exposes sensitive connection data, including session cookies.

Exploitation Process and Risks

Researchers demonstrated that manipulating requests to the /ws endpoint can trigger the unintended disclosure of internal session data. These session cookies act as temporary login credentials, potentially allowing unauthorized access to authenticated sessions without traditional security checks.

The situation becomes particularly critical if an administrator’s session cookie is compromised. The PoC illustrates how an attacker can exploit this to modify the application directory, embedding malicious files and enabling remote code execution via Zammad’s package installation feature.

Call to Action for Administrators

Given the severity of the threat, administrators are urged to update Zammad to version 7 or isolate affected systems. The DIVD has provided a script to help identify signs of session cookie leaks in logs. As exploitation may have occurred before the vulnerability’s public disclosure, it is vital to preserve logs before making any system changes.

Addressing this vulnerability goes beyond patching; it requires a thorough investigation of potential past exposures to mitigate further risks effectively.

Cyber Security News Tags:CVE-2026-102489, Cybersecurity, DIVD, Horizon3.ai, PoC, remote code execution, session leak, Vulnerability, WebSocket, Zammad

Post navigation

Previous Post: Hackers Exploit Atlassian Vulnerability Soon After Disclosure

Related Posts

Edge Extension Malware Exploits Chrome Protocol Edge Extension Malware Exploits Chrome Protocol Cyber Security News
CISA Issues Alert on Exploited cPanel Vulnerability CISA Issues Alert on Exploited cPanel Vulnerability Cyber Security News
Kimsuky Deploys AsyncRAT Using AI and GitHub Tactics Kimsuky Deploys AsyncRAT Using AI and GitHub Tactics Cyber Security News
Network Communication Blocker Tool That Neutralizes EDR/AV Network Communication Blocker Tool That Neutralizes EDR/AV Cyber Security News
Critical Citrix 0-Day Vulnerability Exploited Since May, Leaving Global Entities Exposed Critical Citrix 0-Day Vulnerability Exploited Since May, Leaving Global Entities Exposed Cyber Security News
WordPress Security Breach Deploys Amatera Stealer WordPress Security Breach Deploys Amatera Stealer Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Zammad Flaw Allows Remote Code Execution via Session Leak
  • Hackers Exploit Atlassian Vulnerability Soon After Disclosure
  • AI Tool ARTEX Exploited in South Korean Data Breaches
  • Critical LMCache Vulnerability Allows Unauthorized Code Execution
  • Cisco Releases Patches for Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Zammad Flaw Allows Remote Code Execution via Session Leak
  • Hackers Exploit Atlassian Vulnerability Soon After Disclosure
  • AI Tool ARTEX Exploited in South Korean Data Breaches
  • Critical LMCache Vulnerability Allows Unauthorized Code Execution
  • Cisco Releases Patches for Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark