Cyber Security News

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that can expose active users’ session cookies and enable remote code execution (RCE) as the Zammad operating system user.

This flaw was reportedly exploited during the September breach of the Dutch Institute for Vulnerability Disclosure (DIVD), alongside a separate local privilege escalation issue tracked as CVE-2026-102490.

Zammad Vulnerability

Horizon3.ai’s Attack Team published technical details and exploit code on October 7, revealing that an unauthenticated attacker can send a crafted message to Zammad’s WebSocket endpoint (/ws).

This malformed event triggers an application error, causing the response to include the internal state of connected clients, such as HTTP Cookie headers and valid _zammad_session values.

The vulnerability originates from how Zammad handles Ruby WebSocket events. The application maintains connected-client data in a global @clients object, which includes request headers.

When the provided event name resolves to `Sessions::Event::Base`, Zammad attempts to instantiate the class using the client registry. However, the base handler does not implement the expected `run()` method, resulting in a Ruby NoMethodError.

Instead of returning a sanitized failure response, the vulnerable code returns an error string that includes the object representation, revealing instance variables and the @clients registry. As a result, an attacker can disclose session data from active connected users.

For the public PoC to work, at least one authenticated user must be connected to the WebSocket service during the exploitation. An attacker then needs to identify a usable privileged session cookie, ideally one associated with an administrator account, to further their attack.

According to Horizon3.ai, if an attacker hijacks an administrator session, they can exploit Zammad’s package-installation functionality to write attacker-controlled files into the application directory. The PoC reportedly installs a malicious ERB template that replaces the built-in password reset email view.

By initiating a password reset, the attacker causes Zammad’s mailer component to render the modified template. Because ERB templates can execute Ruby code during server-side rendering, this enables the session takeover to escalate to arbitrary command execution under the Zammad operating system account. The exploit also cleans up the installed package after execution, potentially minimizing obvious artifacts.

DIVD reported that attackers first accessed its systems on September 21, and detected malicious activity the following day. They attributed the initial access to two previously unknown Zammad vulnerabilities: CVE-2026-102489, which allows session hijacking and RCE, and CVE-2026-102490, which elevates privileges from the Zammad user to root.

DIVD characterized the intrusion as an alleged “agentic AI-powered attack,” citing forensic artifacts and attacker scripts. However, their investigation is ongoing, and they have not yet established a connection to any known public threat actor.

Exploit in action (Source: horizon3)

Network segmentation and incident-response actions limited further movement. However, the organization confirmed that volunteer-related data, including email addresses and possibly contact information, may have been exposed.

DIVD lists Zammad versions 6.3.0 through 6.5.4 as vulnerable to the session hijack-to-RCE chain. Versions 7.0.0 through 7.1.3 reportedly contain the flaw but are not exploitable under the environmental conditions DIVD identified. CVE-2026-102490 affects Zammad versions 1.5.0 through 7.1.0-alpha and enables local privilege escalation.

The release of functional exploit code underscores the urgency for defenders: an unauthenticated disclosure bug can quickly become a direct RCE pathway when an active privileged session is available.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 minutes ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

32 minutes ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

1 hour ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

2 hours ago

wolfSSH Patches 5 Security Vulnerabilities, Including Critical SSH Authentication Bypass

wolfSSL has released wolfSSH version 1.6.0, which addresses five security vulnerabilities, including a critical flaw…

2 hours ago

Critical Gitea Vulnerabilities Allow Attackers to Bypass Authentication and Execute Code

Gitea has released version 28.0.0, addressing 20 vulnerabilities related to authentication bypass, unauthorized workflow execution,…

3 hours ago