Impact
A session hijack flaw in Zammad allows an attacker to take control of a user session and execute arbitrary code as the dedicated zammad system user. The vulnerability originates from inadequate protection of session tokens, enabling an unauthenticated or low‑privilege attacker to inject malicious commands through a hijacked session. The direct consequence is full compromise of the affected Zammad instance, with the attacker able to modify data, exfiltrate information, or install persistent backdoors. The weakness aligns with improper access control and session‑management flaws.
Affected Systems
Zammad offered by Zammad GmbH is affected in versions 6.3.0 through 6.5.4; later versions 7.0.0 through 7.1.3 contain the same code but are not exploitable under current environmental conditions. No other vendors or product lines are listed. Users should verify the exact build they run.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. The EPSS score is not available, rendering the exact exploitation likelihood uncertain, yet the high severity combined with the lack of mitigations suggests a significant risk. The vulnerability is not yet catalogued in CISA KEV, implying no widespread exploitation has been reported, but the potential for zero‑day impact remains. Attackers would need the ability to obtain a session token or otherwise hijack a session, likely through network interference or user interaction, to trigger remote code execution.
OpenCVE Enrichment