CVE-2026-102489 is an unauthenticated session disclosure vulnerability in Zammad's WebSocket event handling that enables session hijacking and, when an administrator session is compromised, remote code execution. A crafted base event instantiates Sessions::Event::Base with the global connection registry. Calling its unimplemented run method raises a Ruby NoMethodError whose message includes connection data and authenticated users' session cookies. Returning this error to the requester exposes cookies that can be replayed to impersonate users. An administrator session enables abuse of package installation to overwrite an email template with malicious ERB code; triggering password-reset email rendering executes that code as the low-privileged zammad operating-system account. Versions 6.3.0 through 6.5.4 are described as exploitable, although structured version records inconsistently exclude 6.5.4. The defective code also exists in early 7.x releases, with descriptions variously ending at 7.1.2 or 7.1.3, but framework or runtime changes reportedly prevent exploitation in those releases.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains six files: one README, three Ruby programs, and two POSIX shell scripts. It is a standalone laboratory reproduction, not a framework module or a working exploit against live Zammad. minibox_server.rb replaces WebSocket framing with newline-delimited JSON over TCP, keeps every connected client's handshake headers in a shared registry, deliberately invokes the nonexistent registry method foo, logs e.inspect, and returns e.message to the requesting client. On a Ruby runtime that includes the hash receiver in the exception text, this exposes other clients' cookies. minibox_attack.rb creates both the synthetic victim and unauthenticated attacker, sends the trigger event, extracts the hardcoded victim cookie's token, and submits a login event with that token. The server's fake session store then associates the attacker connection with admin@example.com. The actual production event needed to trigger the exception is explicitly undisclosed, and no RCE or post-exploitation payload is supplied. ruby_behavior_probe.rb isolates the exception-rendering dependency and exits with status 1 when cookie material appears. ioc_check.sh searches ordinary and compressed logs for ERROR lines containing a Cookie hash entry or @clients registry, reports matching lines, and prints distinct exposed cookies. It returns status 0 whether indicators are present or absent, so automation must inspect its output. ioc_check_test.sh feeds it a synthetic matching log line and conditionally downloads the scanner if missing; it does not assert the result. Its rm -rf operation is scoped to a generated temporary directory and is ordinary cleanup, not evidence of a fake exploit. Important limitations include a possible timing race between registration of the victim connection and the attacker's trigger, hardcoded token extraction, and loopback-only server binding, which also means the README's published-port Docker example does not by itself make the service reachable through the container interface. The README attributes CVE-2026-102489 to Zammad 6.3.x–6.5.x and claims a subsequent RCE chain, real-world exploitation, and KEV inclusion; these external claims are not verified by the supplied files. Repository URL, revision, and archive size were not supplied; the listed file sizes total 19,462 bytes, which is not an archive-size measurement.
The supplied repository contains two files: a standalone Python exploit (7,574 bytes) and a README (2,706 bytes). The Python script embeds a Ruby ERB command-execution payload; no exploit framework, dependency manifest, or tests are present. It sends an unauthenticated WebSocket event named base, expecting a Ruby NoMethodError to disclose the shared @clients map and connected users' session cookies. It validates those cookies through the users/me API, preferentially selects a session containing role ID 1, obtains a CSRF token, and uploads the ZammadRceAddon package containing a malicious password-reset mailer template. A password-reset request then attempts to execute the operator's command, defaulting to id, as the Zammad service user. Cleanup attempts package removal but suppresses exceptions and does not explicitly remove the output file. The script reports execution after a fixed delay without verifying output, so its success messages are not proof of compromise. HTTP requests disable TLS certificate verification. No reverse shell, external exfiltration destination, or direct command-output retrieval is implemented. The repository claims CVE-2026-102489 affects Zammad <= 6.5.4 and is fixed in 7.2.0; these claims and runtime exploitability cannot be independently verified from the supplied files. The Git reference and archive size were not supplied: ref is empty and size_bytes is 0 to represent unavailable metadata; the listed file sizes total 10,280 bytes.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
112 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical unauthenticated session disclosure vulnerability in Zammad's WebSocket event handling, rated CVSS 3.x 9.8. Crafted events expose connected users' session cookies, enabling session hijacking. Hijacking an administrator session can lead to remote code execution as the zammad system user and access to support tickets, customer records, and credentials. Exploitation in the wild is reported, and CISA added it to the KEV catalog on October 2, 2026. Affected-version reporting conflicts over whether 6.5.4 is vulnerable; it should not be treated as confirmed fixed. Vulnerable code reportedly exists in 7.0.0–7.1.3 but is not exploitable in that runtime environment. Zammad recommends upgrading to 7.2.0 or a later supported release, which includes code hardening.
An unauthenticated WebSocket information leak in Zammad exposes active users' session cookies through error handling at the /ws endpoint. An attacker can hijack an administrator session and abuse package installation to achieve remote code execution as the Zammad service account, not root. Exploitation requires at least one authenticated user connected to the WebSocket endpoint. Versions 6.3.0–6.5.4 are exploitable; versions 7.0.0–7.1.3 retain the code issue but reportedly lack the environmental conditions needed for exploitation. The flaw was reportedly exploited in the September DIVD breach, and Horizon3.ai published a public PoC.
An unauthenticated WebSocket information leak in Zammad can disclose active users' session cookies through error responses to requests at /ws. Attackers can hijack sessions without passwords or MFA; stealing an administrator's session enables abuse of package installation and ERB templates to execute code as the low-privileged Zammad service account. Exploitation requires at least one authenticated user connected to the WebSocket endpoint. Versions 6.3.0–6.5.4 are exploitable; versions 7.0.0–7.1.3 contain the same code issue but reportedly lack the environmental conditions necessary for exploitation. The flaw was reportedly exploited in the September DIVD breach.
A session leak vulnerability in Zammad that researchers demonstrated could enable administrator session hijacking and lead to remote code execution. The content describes research exploitation, not confirmed exploitation in the wild.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.