PoC Released for Zammad Session Leak Flaw Enabling Remote Code Execution
Horizon3.ai released a PoC for Zammad CVE-2026-102489 that leaks session cookies and can yield remote code execution.
Horizon3.ai published a proof-of-concept for CVE-2026-102489, a Zammad WebSocket session leak in versions 6.3.0 through 6.5.4. An unauthenticated request can expose logged-in users’ session cookies, and a stolen administrator session can install packages that plant malicious ERB templates for remote code execution as the Zammad service account. The Dutch Institute for Vulnerability Disclosure traced a September intrusion to this bug and to CVE-2026-102490, a still-undetailed local privilege escalation. Versions 7.0.0–7.1.3 share the code issue but were not considered exploitable; DIVD advises upgrading to version 7 and preserving logs.
- CVE-2026-102489 leaks active Zammad session cookies through the /ws WebSocket endpoint.
- Horizon3.ai's PoC hijacks admin sessions and abuses package installs for code execution.
- Affected releases are Zammad 6.3.0 through 6.5.4; upgrading to version 7 is advised.
- DIVD was breached in September using two Zammad zero-days, including CVE-2026-102490.
- Exploitation requires at least one authenticated user connected to the WebSocket.
Vulnerabilities mentionedAll →
- CVE-2026-1024899.41%Session hijack to RCE in Zammadpublished · Zammad KEV PoC +1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | horizon3.ai | inistrator’s cookie is compromised. The PoC demonstrated by Horizon3.ai shows that an attacker who hijacks an admin session can exp |
Full article597 words · extracted from cybersecuritynews.com · click to collapse
A public PoC targets a critical Zammad flaw, CVE-2026-102489, allowing unauthenticated remote users to steal active session cookies and potentially execute code on vulnerable servers.
The issue was associated with a breach reported in September at the Dutch Institute for Vulnerability Disclosure (DIVD), where two zero-day flaws in Zammad were reportedly exploited to gain access and escalate privileges.
The flaw affects Zammad versions 6.3.0 to 6.5.4 and is exploitable, while versions 7.0.0 to 7.1.3 contain the same code issue but lack the environmental conditions for exploitation, as DIVD noted.
The PoC, published by Horizon3.ai, exploits a WebSocket information leak that can lead to session hijacking and remote code execution as a low-privileged Zammad operating system user.
Understanding how this session leak operates is essential for remediation. The vulnerability arises from Zammad’s WebSocket event handling mechanism.
PoC Released for Zammad Session Leak Flaw
Researchers discovered that sending a request to the /ws endpoint with the payload {"event":"base"} could trigger an application error. Instead of returning a benign error message, the server response might inadvertently disclose internal data associated with active WebSocket connections.
This leaked internal data could include the _zammad_session cookies of users currently logged into the application. A session cookie functions like a temporary login key, granting access to an authenticated session without needing to enter a password or pass multi-factor authentication checks.
The vulnerability stems from how Zammad handles live connection data stored in the @clients object, including request headers such as the Cookie header. When an error occurs, the event handling code can return an object that reveals these sensitive values to whoever requested it.

The implications of this session leak escalate significantly when an administrator’s cookie is compromised. The PoC demonstrated by Horizon3.ai shows that an attacker who hijacks an admin session can exploit Zammad’s package installation feature to write malicious files into the application directory.
This self-propagating threat can replace email templates with harmful ERB code, enabling remote code execution under the Zammad service account, though not as root.
The PoC indicates that for the exploitation to be effective, at least one authenticated user must be connected to the WebSocket endpoint when the attack occurs.
This reality makes public-facing Zammad servers particularly vulnerable and requires immediate investigation. Helpdesk systems often hold sensitive information, including support conversations, customer details, and internal operations, making them attractive targets for attackers.
The breach at DIVD was identified after unusual activity was detected on September 22, following an intrusion on September 21. This breach was traced back to two zero-day vulnerabilities in Zammad.
The first flaw, CVE-2026-102489, concerns session hijacking and remote code execution. The second flaw, CVE-2026-102490, poses a local privilege escalation risk that could enable the Zammad user to achieve root access. Detailed technical information about the latter flaw remains confidential, as it was reportedly unpatched at the time of disclosure.
In light of these findings, Zammad administrators should urgently update to version 7 or take affected systems offline. DIVD has also released a script for identifying potential evidence of leaked session cookies in Zammad logs.
Because the vulnerability may have been exploited before public disclosure, teams must preserve logs before any system changes or rebuilds. Administrators should treat this PoC not merely as a patching task but as a prompt to assess previous exposure and remediate effectively.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.