Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-102489 — Proof-of-concept exploit for CVE-2026-102489 in Zammad: chains a WebSocket session leak into authenticated session hijacking and unauthenticated remote code execution. | Kitploit
Tools/GitHubGitHub/horizon3ai/cve-2026-102489
Vulnerability AnalysisExploitationWeb Application ExploitationPost-ExploitationWeb SecurityRemote Access ToolPayload Development
GitHubhorizon3ai/cve-2026-102489

CVE-2026-102489

Proof-of-concept exploit for CVE-2026-102489 in Zammad: chains a WebSocket session leak into authenticated session hijacking and unauthenticated remote code execution.

View Repository
115h 18m agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-102489: Zammad Unauthenticated Remote Code Execution

This repository contains a proof of concept for CVE-2026-102489, an unauthenticated remote code execution vulnerability in Zammad. The exploit chains a WebSocket information disclosure flaw into authenticated session takeover and arbitrary command execution as the zammad OS user.

Vulnerability Details

Sessions::Event::Base is a valid Ruby constant that has no run() method. Sending {"event":"base"} over the WebSocket endpoint raises a NoMethodError whose message includes the full receiver inspect — which contains @clients, the live map of every connected user's request context, including their Cookie header.

The PoC leverages this leak to:

  1. Harvest valid _zammad_session cookies from connected users via the WebSocket @clients disclosure.
  2. Identify and hijack an authenticated (ideally admin) session.
  3. Install a malicious ERB template through the package API, overwriting the password-reset mailer view.
  4. Trigger server-side template evaluation via a password reset to execute an arbitrary command, then clean up the installed package.

Blog Post

Technical analysis covering root cause, exploitation, and indicators of compromise is available on the Horizon3.ai attack research blog:

https://horizon3.ai/attack-research/disclosures/cve-2026-102489-zammad-session-leak-rce/

Usage

% python3 CVE-2026-102489.py -h
usage: CVE-2026-102489.py [-h] -u URL [-c COMMAND] [--out-file OUT_FILE]

options:
  -h, --help            show this help message and exit
  -u URL, --url URL     The base URL of the target
  -c COMMAND, --command COMMAND
                        Command to execute on the target
  --out-file OUT_FILE   Output file path on the target (default:
                        /tmp/zammad_rce.txt)

Run with the default id command:

python3 CVE-2026-102489.py -u http://zammad.example.com

Execute an arbitrary command:

python3 CVE-2026-102489.py -u http://zammad.example.com -c 'id'

Note: The information disclosure requires at least one authenticated user to be connected to the WebSocket endpoint at the time of exploitation.

Follow Horizon3.ai Attack Team for Latest Security Research

  • Horizon3 Attack Team

Disclaimer

"This software has been created purely for the purposes of academic research and for the development of effective defensive techniques, and is not intended to be used to attack systems except where explicitly authorized." Project maintainers assume no liability for misuse. Use responsibly.

Download Tool