PULSE
FEED
ransomqilin reclama a Thai Lion Air · TH · Transportationransomrhysida reclama a Mat Bao Corporation · VN · Technologyransompanzer reclama a Paessolucoes · BR · Otherransomrhysida reclama a Electro Heat Sweden AB · SE · Energy & Utilitiesransomqilin reclama a Sports Events365 · GB · Hospitalityransomauditteam reclama a Ad***ng · AE · Technologyransomakira reclama a The Official College of Architects of León (COAL) · MX · Professional Servicesransomakira reclama a Jampac Alimentos · BR · Agriculture and Food Productionransomakira reclama a Pacific Tank Lines · US · Transportationransomqilin reclama a Inova Semiconductors GmbH · DE · Manufacturingransombooba project reclama a Raleigh Family Medicine · US · Healthcareransombooba project reclama a EdgeEndo® USA · US · Healthcareransombooba project reclama a Soni Medical Centre · CA · Healthcareransombooba project reclama a University of Illinois Chicago · US · Educationransomqilin reclama a Thai Lion Air · TH · Transportationransomrhysida reclama a Mat Bao Corporation · VN · Technologyransompanzer reclama a Paessolucoes · BR · Otherransomrhysida reclama a Electro Heat Sweden AB · SE · Energy & Utilitiesransomqilin reclama a Sports Events365 · GB · Hospitalityransomauditteam reclama a Ad***ng · AE · Technologyransomakira reclama a The Official College of Architects of León (COAL) · MX · Professional Servicesransomakira reclama a Jampac Alimentos · BR · Agriculture and Food Productionransomakira reclama a Pacific Tank Lines · US · Transportationransomqilin reclama a Inova Semiconductors GmbH · DE · Manufacturingransombooba project reclama a Raleigh Family Medicine · US · Healthcareransombooba project reclama a EdgeEndo® USA · US · Healthcareransombooba project reclama a Soni Medical Centre · CA · Healthcareransombooba project reclama a University of Illinois Chicago · US · Education
← Todos los CVEs
CVE Watch2 oct 2026

CVE-2026-102489

Zammad GmbH Zammad Session Fixation Vulnerability

CVSS

9.8

Crítico

EPSS

0.6%

p46

KEV

SÍ

2 oct 2026

Exploit Today

64

0-100

Publicado: 30 sept 2026 · Última mod.: 2 oct 2026 · CWE-384

EPSS · 30d
0.6%EPSS · 30 días0.7%
2026-10-012026-10-02
Ficha del catálogo KEV

Producto

Zammad GmbH / Zammad

Vulnerabilidad

Zammad GmbH Zammad Session Fixation Vulnerability

Añadido a KEV

2 oct 2026

Remediar antes de

5 oct 2026

Uso conocido en ransomware

No

Descripción resumida

Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.

Acción requerida

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Notas

https://zammad.com/en/product/releases/ ; https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297/2 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-102489

Descripción técnica

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-1044696.8 MED
—
——0YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID. Attackers who set or learn a victim's pre-authentication YesWiki-* session cookie can reuse it after login to access private content and perform actions with the victim's privileges.16h
CVE-2026-1024909.8 CRÍ
16.3%
KEV—55Zammad GmbH Zammad Improper Privilege Management Vulnerability10h
CVE-2026-713027.1 ALT
19.2%
——6The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and reuse it after victim authentication, resulting in session takeover.3d
CVE-2026-101268—
8.5%
——3If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's customer account. If the victim does not notice this, this might lead to their order details being stored into the attacker's account. The attack only works when the event is available on a different domain than the organizer page.3d
CVE-2026-926099.8 CRÍ
29.5%
——9Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.8d
CVE-2026-571794.2 MED
4.3%
——1Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it. Applications using resumable partial pipeline steps could allow an attacker to start an authentication flow, obtain a valid partial token and verification data, and cause a victim's browser to resume that attacker-controlled flow. This could authenticate the victim's browser as the attacker's account. The issue affects applications using partial pipeline steps such as `mail_validation` or custom steps decorated with `@partial`. The issue has been fixed in version 5.0.0 by binding partial pipeline resumes to the originating browser session.8d