← Back to the feed

~/article/zammad-gmbh-zammad-session-fixation-vulnerability-zhevna
criticalSource: CISA

Zammad GmbH Zammad Session Fixation Vulnerability

Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.

Read at the source

Summary written for cymesh.dev. The full article lives at CISA.

Referenced CVEs

Topics

~/cymesh.net

This is what cymesh.net is for

Certificate and hostname problems are the ones you find out about from your users. cymesh.net finds them first.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks

Related

~/related/zammad-gmbh-zammad-session-fixation-vulnerability-zhevna