Exploited Zammad bug leaks helpdesk session cookies through Ruby error output
CISA added Zammad's unauthenticated WebSocket session-disclosure flaw, CVE-2026-102489, to its exploited-vulnerabilities catalog on October 2. The fix ships in Zammad 7.2.0, leaving teams on the unsupported 6.5-and-earlier releases to make a major-version jump.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+5
- Incentives70
- Confidence55