---
cve: "CVE-2026-102489"
severity: "HIGH"
cvss: 8.7
epss: "1.4%"
vendor: "Zammad GmbH"
kev: true
exploited: true
published: "2026-09-30 17:16:40"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-10-08T21:12:32+02:00"
---

# CVE-2026-102489

> 8.7 HIGH · ⚠️ CISA KEV (8 Tage) · 🔓 Exploited

## Beschreibung

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The bug is also present in version 7.0.0 to version 7.1.2, but not exploitable due to changes in the underlying framework.

## CNA-Record (Kanon, cvelistV5)

- CNA: **DIVD**
- State: PUBLISHED
- Stand: 2026-10-07 14:03:06
- CNA-CVSS: **8.7** (`CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:A/AU:Y/V:C`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA KEV seit: **02.10.2026**
- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **active**
  - Automatable: **yes**
  - Technical Impact: **total**

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:A/AU:Y/V:C
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |

## BSI-Hinweise (deutsch)

- [Zammad: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode und Privilegieneskalation](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3694) — _BSI-Einstufung: kritisch_
  Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Zammad ausnutzen, um beliebigen Programmcode mit Benutzerrechten auszuführen und um Root-Rechte zu erlangen.

## Referenzen

- <https://csirt.divd.nl/DIVD-2026-00015>
- <https://csirt.divd.nl/CVE-2026-102489>
- <https://zammad.com/en/advisories/cve-2026-102489-cve-2026-102490>
- <https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297/2>
- <https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-102489>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/sicherheitsluecken/cve-2026-102489/) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
