Security1 publisherNot yet confirmed elsewhere2 min readPublished
One unauthenticated request to Zammad's /ws endpoint leaks every active user's session cookie
Horizon3 reproduced CVE-2026-102489 and showed one unauthenticated request to Zammad's /ws endpoint reflects every active user's session cookie. A leaked admin cookie opens the second half of the chain, remote code execution.
The Watch · Security desk

What happened
- DIVD disclosed on 24 September 2026 that attackers broke in through its own Zammad helpdesk, the open-source ticketing app that sat at the start of the chain.
- The breach abused two distinct zero-days: the session leak plus a separate privilege-escalation bug, CVE-2026-102490, that reaches root on the host.
- Horizon3 published a working proof-of-concept exploit for the full chain on GitHub.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure The exposed surface is any Zammad with /ws reachable; one unauthenticated request returns the live session cookie of every signed-in user, admin sessions included.
- decision Defenders can act without waiting for a patch: run DIVD's indicator script against existing error logs, since the cookies were written there the moment the trigger fired.
- constraint CVE-2026-102490 is still unpatched, so fixing the session leak alone leaves the second flaw in the chain open.
Zammad keeps every websocket client's state in a class-level variable called @clients. It passes that variable with every event and filters neither by event type nor by the sending client, and the session cookies sit inside its headers key [12]. Send {"event":"base"} to the /ws endpoint and the dispatcher resolves Sessions::Event::Base as a real class, builds it with the whole @clients registry attached, then calls a .run method that Base never implements [10]. Ruby's NoMethodError text includes the receiver's full object, @clients and all, and the code in sessions/event.rb returns that string straight to the caller [13].
Horizon3 did not read the trigger out of the source. It pointed a research harness running Anthropic's Opus 4.8 at DIVD's case files, DIVD's indicator script, and Zammad's public repository [7]. Within a couple of hours the harness confirmed an error would leak the cookie strings but could not reach one without authenticating [8]. Re-prompted to fuzz the websocket code, it hit the reflected error within minutes [9]. DIVD had blamed its own breach on an "agentic AI powered attack" [2]; the public reproduction came from an AI harness aimed at the same code.
CVE-2026-102489 is only the session-hijack half of the chain [4]. The second half needs an admin cookie, which the leak supplies whenever an admin session is active. With one, an attacker writes files into the Zammad application directory through the package-installation endpoint [14], overwrites the password-reset email view with a malicious ERB template, and starts a password reset so the mailer renders it with full Ruby privileges, giving code execution as the zammad OS user [15]. No credential is entered at any step [19]. Horizon3's writeup does not include a fixed version for the session leak [18].
What to watch
- A fixed Zammad version for CVE-2026-102489, which the writeup does not name.
- Public details or a patch for CVE-2026-102490, the root escalation Horizon3 is withholding.
- Reports of in-the-wild scanning of /ws for the {"event":"base"} trigger.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption52
- Hype gap+12
- Incentives65
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
On 24 September 2026, the Dutch Institute for Vulnerability Disclosure (DIVD) publicly announced it had suffered a security incident and attributed the source of the initial breach to Zammad, a helpdesk and ticketing application.
- [2]
DIVD attributed the incident to an "agentic AI powered attack" given the forensic artifacts it discovered during incident response.
- [3]
DIVD determined that two distinct 0-day vulnerabilities were abused in the incident.
- [4]
CVE-2026-102489 is a session hijack that ultimately allows executing code as the zammad user.
- [5]
CVE-2026-102490 is a privilege escalation that allows escalating to root.
- [6]
DIVD released further details of the Zammad vulnerabilities and released an Indicators of Compromise script that looks for leaked session cookies in error logs.
- [7]
Horizon3 prompted a vulnerability research harness using Anthropic's Opus 4.8 model, giving it the DIVD CSIRT cases, the DIVD IOC script, and the Zammad open-source GitHub repository.
- [8]
After a couple hours, the harness confirmed that triggering an error would leak the session cookie strings but was unable to find an unauthenticated trigger request.
- [9]
Re-prompted to build fuzzing tooling, the agent, several minutes into a fuzzing campaign against the websocket code, triggered an error reflected back to the requestor that contained the session cookies.
- [10]
The vulnerability trigger is a single request to the WebSocket endpoint /ws with a payload of {"event":"base"}.
- [11]
The server reflects the error back to the client, which leaks the cookies for all active users.
- [12]
Zammad is a Ruby application that uses websockets and stores all global connection state in the @clients class-level instance variable, which is passed with every event with no event-type or client-based filtering; the sensitive cookies are stored inside the headers key of that variable.
- [13]
When a client sends {"event":"base"}, the dispatcher resolves Sessions::Event::Base, instantiates it with the full @clients registry mass-assigned, then fails when .run is called because Base has no implementation; Ruby builds a NoMethodError message that includes the receiver's full object representation, every instance variable including @clients, and sessions/event.rb returns that message string directly to the caller.
- [14]
Once an attacker has a valid admin session cookie, they can write arbitrary files into the Zammad application directory via the package installation endpoint.
- [15]
By writing a malicious ERB template that overrides the built-in password reset email view and initiating a password reset for any user, the attacker causes Zammad's mailer to render the attacker-controlled template with full Ruby execution, achieving remote code execution as the zammad OS user.
- [16]
Horizon3 published a proof-of-concept exploit for CVE-2026-102489 on GitHub.
- [17]
Horizon3 said the privilege-escalation vector it believes to be CVE-2026-102490 remains unpatched, and that it is withholding those details.
- [18]
Horizon3's writeup does not include a fixed Zammad version for the session-leak vulnerability.
- [19]
Chained, an unauthenticated attacker who can reach /ws obtains an admin session cookie whenever an admin session is live and then runs code as the zammad user without supplying any credential.
Sources
1 independent publisher whose own reporting we read for this story.
- horizon3.aiZammad CVE-2026-102489: Session Leak to RCE
1 article · October 7, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Zero-Day VulnerabilitiesFollow
- Session and Cookie HijackingFollow
- Agentic AI in Offensive SecurityFollow