CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability
Summary
A session fixation vulnerability has been identified in Zammad GmbH Zammad, potentially leading to remote code execution as the zammad user. This flaw can be exploited in conjunction with CVE-2026-102490. Organizations are instructed to apply vendor mitigations, follow CISA's guidance on prioritizing security updates, and assess their cloud service configurations.
IFF Assessment
The session fixation vulnerability allows for remote code execution, posing a significant risk to defenders.
Severity
This vulnerability allows for remote code execution and can be chained with another vulnerability, indicating a high impact and exploitability.
CISA KEV: Listed as actively exploited. Federal patch due: October 05, 2026. Known ransomware use: Unknown.
Defender Context
This vulnerability highlights the ongoing risks associated with session management in web applications. Defenders should prioritize patching or mitigating this flaw, especially given its potential for chained exploitation and remote code execution. It is crucial to follow CISA's guidance for timely risk-based patching and to diligently assess the internet exposure of affected assets.