U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog
Brief
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog.
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog :
- CVE-2026-102489 (CVSS score of 9.4) Zammad GmbH Zammad Session Fixation Vulnerability
- CVE-2026-102490 (CVSS score of 9.4) Zammad GmbH Zammad Improper Privilege Management Vulnerability
The first flaw, CVE-2026-102489, is a session hijacking vulnerability in Zammad that can lead to remote code execution as the zammad user. It affects Zammad 6.
- 0 through 6.
- 4. The flaw is also present in versions 7.
- 0 through 7.
- 3.
The second flaw, CVE-2026-102490, is a local privilege escalation vulnerability that allows the zammad user to gain root privileges.
