EUVD Vulnerability Catalog Actively Exploited (KEV)

EUVD-2026-90080

Severity: HIGH Base Score: 8.7 CVSS Version: 4.0

Vulnerability Description

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

CVSS Vector Analysis

Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:A/AU:Y/V:C

▪ Attack Vector (AV): Network
▪ Attack Complexity (AC): Low
▪ Attack Requirements (AT): None
▪ Privileges Required (PR): None
▪ User Interaction (UI): Passive
▪ Vulnerability Confidentiality Impact (VC): High
▪ Vulnerability Integrity Impact (VI): High
▪ Vulnerability Availability Impact (VA): High
▪ Subsequent Confidentiality Impact (SC): Low
▪ Subsequent Integrity Impact (SI): Low
▪ Subsequent Availability Impact (SA): Low
▪ E: Adjacent
▪ AU: Y
▪ V: Changed

Affected Vendors & Systems

Vendor Zammad GmbH

References & Advisory Links

Metadata Profile

Database Authority

European Union Agency for Cybersecurity (ENISA) EUVD

Assigner

DIVD

EPSS Probability

0

Known Aliases
GHSA-xmw5-m2wg-4243 CVE-2026-102489
Published On

2026-09-30

Last Updated

2026-09-30

Exploited Since

2026-09-30