PoC Released for Zammad Session Leak Flaw Enabling Remote Code Execution

A public PoC targets a critical Zammad flaw, CVE-2026-102489, allowing unauthenticated remote users to steal active session cookies and potentially execute code on vulnerable servers. The issue was associated with a breach reported in September at the Dutch Institute for Vulnerability Disclosure (DIVD), where two zero-day flaws in Zammad were reportedly exploited to gain access and […]

This article has been indexed from Cyber Security News

Read the original article: