First published · Last updated
CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability
CVE-2026-102489 is a session fixation vulnerability in Zammad GmbH’s Zammad that can be chained with CVE-2026-102490 and can lead to remote code execution as the zammad user. CISA advises applying vendor mitigations per its BOD 26-04 guidance or discontinuing use if mitigations are unavailable.
Categories: technology
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 8/10
- Geographic reach
- 4/10
- Global importance
- 4/10
- Impact magnitude
- 4/10
- Positivity
- 2/10
- Urgency
- 6/10
Why it matters
Unmitigated exploitation can result in remote code execution on affected systems and requires stakeholders to follow CISA patching and mitigation guidance.

