PoC Released for Zammad Session Leak Flaw Enabling Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A public PoC targets a critical Zammad flaw, CVE-2026-102489, allowing unauthenticated remote users to steal active session cookies and potentially execute code on vulnerable servers.

The issue was associated with a breach reported in September at the Dutch Institute for Vulnerability Disclosure (DIVD), where two zero-day flaws in Zammad were reportedly exploited to gain access and escalate privileges.

The flaw affects Zammad versions 6.3.0 to 6.5.4 and is exploitable, while versions 7.0.0 to 7.1.3 contain the same code issue but lack the environmental conditions for exploitation, as DIVD noted.

The PoC, published by Horizon3.ai, exploits a WebSocket information leak that can lead to session hijacking and remote code execution as a low-privileged Zammad operating system user.

Understanding how this session leak operates is essential for remediation. The vulnerability arises from Zammad’s WebSocket event handling mechanism.

PoC Released for Zammad Session Leak Flaw

Researchers discovered that sending a request to the /ws endpoint with the payload {"event":"base"} could trigger an application error. Instead of returning a benign error message, the server response might inadvertently disclose internal data associated with active WebSocket connections.

This leaked internal data could include the _zammad_session cookies of users currently logged into the application. A session cookie functions like a temporary login key, granting access to an authenticated session without needing to enter a password or pass multi-factor authentication checks.

The vulnerability stems from how Zammad handles live connection data stored in the @clients object, including request headers such as the Cookie header. When an error occurs, the event handling code can return an object that reveals these sensitive values to whoever requested it.

 Exploit in action (Source: horizon3)
Exploit in action (Source: Horizon3)

The implications of this session leak escalate significantly when an administrator’s cookie is compromised. The PoC demonstrated by Horizon3.ai shows that an attacker who hijacks an admin session can exploit Zammad’s package installation feature to write malicious files into the application directory.

This self-propagating threat can replace email templates with harmful ERB code, enabling remote code execution under the Zammad service account, though not as root.

The PoC indicates that for the exploitation to be effective, at least one authenticated user must be connected to the WebSocket endpoint when the attack occurs.

This reality makes public-facing Zammad servers particularly vulnerable and requires immediate investigation. Helpdesk systems often hold sensitive information, including support conversations, customer details, and internal operations, making them attractive targets for attackers.

The breach at DIVD was identified after unusual activity was detected on September 22, following an intrusion on September 21. This breach was traced back to two zero-day vulnerabilities in Zammad.

The first flaw, CVE-2026-102489, concerns session hijacking and remote code execution. The second flaw, CVE-2026-102490, poses a local privilege escalation risk that could enable the Zammad user to achieve root access. Detailed technical information about the latter flaw remains confidential, as it was reportedly unpatched at the time of disclosure.

In light of these findings, Zammad administrators should urgently update to version 7 or take affected systems offline. DIVD has also released a script for identifying potential evidence of leaked session cookies in Zammad logs.

Because the vulnerability may have been exploited before public disclosure, teams must preserve logs before any system changes or rebuilds. Administrators should treat this PoC not merely as a patching task but as a prompt to assess previous exposure and remediate effectively.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post PoC Released for Zammad Session Leak Flaw Enabling Remote Code Execution appeared first on Cyber Security News.