A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that can expose active users’ session cookies and enable remote code execution (RCE) as the Zammad operating system user.
This flaw was reportedly exploited during the September breach of the Dutch Institute for Vulnerability Disclosure (DIVD), alongside a separate local privilege escalation issue tracked as CVE-2026-102490.
Horizon3.ai’s Attack Team published technical details and exploit code on October 7, revealing that an unauthenticated attacker can send a crafted message to Zammad’s WebSocket endpoint (/ws).
This malformed event triggers an application error, causing the response to include the internal state of connected clients, such as HTTP Cookie headers and valid _zammad_session values.
The vulnerability originates from how Zammad handles Ruby WebSocket events. The application maintains connected-client data in a global @clients object, which includes request headers.
When the provided event name resolves to `Sessions::Event::Base`, Zammad attempts to instantiate the class using the client registry. However, the base handler does not implement the expected `run()` method, resulting in a Ruby NoMethodError.
Instead of returning a sanitized failure response, the vulnerable code returns an error string that includes the object representation, revealing instance variables and the @clients registry. As a result, an attacker can disclose session data from active connected users.
For the public PoC to work, at least one authenticated user must be connected to the WebSocket service during the exploitation. An attacker then needs to identify a usable privileged session cookie, ideally one associated with an administrator account, to further their attack.
According to Horizon3.ai, if an attacker hijacks an administrator session, they can exploit Zammad’s package-installation functionality to write attacker-controlled files into the application directory. The PoC reportedly installs a malicious ERB template that replaces the built-in password reset email view.
By initiating a password reset, the attacker causes Zammad’s mailer component to render the modified template. Because ERB templates can execute Ruby code during server-side rendering, this enables the session takeover to escalate to arbitrary command execution under the Zammad operating system account. The exploit also cleans up the installed package after execution, potentially minimizing obvious artifacts.
DIVD reported that attackers first accessed its systems on September 21, and detected malicious activity the following day. They attributed the initial access to two previously unknown Zammad vulnerabilities: CVE-2026-102489, which allows session hijacking and RCE, and CVE-2026-102490, which elevates privileges from the Zammad user to root.
DIVD characterized the intrusion as an alleged “agentic AI-powered attack,” citing forensic artifacts and attacker scripts. However, their investigation is ongoing, and they have not yet established a connection to any known public threat actor.
Network segmentation and incident-response actions limited further movement. However, the organization confirmed that volunteer-related data, including email addresses and possibly contact information, may have been exposed.
DIVD lists Zammad versions 6.3.0 through 6.5.4 as vulnerable to the session hijack-to-RCE chain. Versions 7.0.0 through 7.1.3 reportedly contain the flaw but are not exploitable under the environmental conditions DIVD identified. CVE-2026-102490 affects Zammad versions 1.5.0 through 7.1.0-alpha and enables local privilege escalation.
The release of functional exploit code underscores the urgency for defenders: an unauthenticated disclosure bug can quickly become a direct RCE pathway when an active privileged session is available.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…
wolfSSL has released wolfSSH version 1.6.0, which addresses five security vulnerabilities, including a critical flaw…
Gitea has released version 28.0.0, addressing 20 vulnerabilities related to authentication bypass, unauthorized workflow execution,…