Skip to content

Security1 publisherNot yet confirmed elsewhere2 min readPublished

One unauthenticated request to Zammad's /ws endpoint leaks every active user's session cookie

Horizon3 reproduced CVE-2026-102489 and showed one unauthenticated request to Zammad's /ws endpoint reflects every active user's session cookie. A leaked admin cookie opens the second half of the chain, remote code execution.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying One unauthenticated request to Zammad's /ws endpoint leaks every active user's session cookie
Generated illustration

What happened

  • DIVD disclosed on 24 September 2026 that attackers broke in through its own Zammad helpdesk, the open-source ticketing app that sat at the start of the chain.
  • The breach abused two distinct zero-days: the session leak plus a separate privilege-escalation bug, CVE-2026-102490, that reaches root on the host.
  • Horizon3 published a working proof-of-concept exploit for the full chain on GitHub.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure The exposed surface is any Zammad with /ws reachable; one unauthenticated request returns the live session cookie of every signed-in user, admin sessions included.
  • decision Defenders can act without waiting for a patch: run DIVD's indicator script against existing error logs, since the cookies were written there the moment the trigger fired.
  • constraint CVE-2026-102490 is still unpatched, so fixing the session leak alone leaves the second flaw in the chain open.

Zammad keeps every websocket client's state in a class-level variable called @clients. It passes that variable with every event and filters neither by event type nor by the sending client, and the session cookies sit inside its headers key [12]. Send {"event":"base"} to the /ws endpoint and the dispatcher resolves Sessions::Event::Base as a real class, builds it with the whole @clients registry attached, then calls a .run method that Base never implements [10]. Ruby's NoMethodError text includes the receiver's full object, @clients and all, and the code in sessions/event.rb returns that string straight to the caller [13].

Horizon3 did not read the trigger out of the source. It pointed a research harness running Anthropic's Opus 4.8 at DIVD's case files, DIVD's indicator script, and Zammad's public repository [7]. Within a couple of hours the harness confirmed an error would leak the cookie strings but could not reach one without authenticating [8]. Re-prompted to fuzz the websocket code, it hit the reflected error within minutes [9]. DIVD had blamed its own breach on an "agentic AI powered attack" [2]; the public reproduction came from an AI harness aimed at the same code.

CVE-2026-102489 is only the session-hijack half of the chain [4]. The second half needs an admin cookie, which the leak supplies whenever an admin session is active. With one, an attacker writes files into the Zammad application directory through the package-installation endpoint [14], overwrites the password-reset email view with a malicious ERB template, and starts a password reset so the mailer renders it with full Ruby privileges, giving code execution as the zammad OS user [15]. No credential is entered at any step [19]. Horizon3's writeup does not include a fixed version for the session leak [18].

What to watch

  • A fixed Zammad version for CVE-2026-102489, which the writeup does not name.
  • Public details or a patch for CVE-2026-102490, the root escalation Horizon3 is withholding.
  • Reports of in-the-wild scanning of /ws for the {"event":"base"} trigger.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption52
Hype gap+12
Incentives65
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    On 24 September 2026, the Dutch Institute for Vulnerability Disclosure (DIVD) publicly announced it had suffered a security incident and attributed the source of the initial breach to Zammad, a helpdesk and ticketing application.

    ReportedSupportedView cited source
  2. [2]

    DIVD attributed the incident to an "agentic AI powered attack" given the forensic artifacts it discovered during incident response.

    ReportedSupportedView cited source
  3. [3]

    DIVD determined that two distinct 0-day vulnerabilities were abused in the incident.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. horizon3.ai

    1 article · October 7, 2026

    Zammad CVE-2026-102489: Session Leak to RCE

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories