PoC Released for Zammad Session Leak Flaw Enabling Remote Code Execution
A public PoC targets a critical Zammad flaw, CVE-2026-102489, allowing unauthenticated remote users to steal active session cookies and potentially execute code on vulnerable servers. The issue was associated with a breach reported in September at the Dutch Institute for Vulnerability Disclosure...