
Proof-of-concept exploit for CVE-2026-102489 in Zammad: chains a WebSocket session leak into authenticated session hijacking and unauthenticated remote code execution.
This repository contains a proof of concept for CVE-2026-102489, an unauthenticated remote code execution vulnerability in Zammad. The exploit chains a WebSocket information disclosure flaw into authenticated session takeover and arbitrary command execution as the zammad OS user.
Sessions::Event::Base is a valid Ruby constant that has no run() method. Sending {"event":"base"} over the WebSocket endpoint raises a NoMethodError whose message includes the full receiver inspect — which contains @clients, the live map of every connected user's request context, including their Cookie header.
The PoC leverages this leak to:
_zammad_session cookies from connected users via the WebSocket @clients disclosure.Technical analysis covering root cause, exploitation, and indicators of compromise is available on the Horizon3.ai attack research blog:
https://horizon3.ai/attack-research/disclosures/cve-2026-102489-zammad-session-leak-rce/
% python3 CVE-2026-102489.py -h
usage: CVE-2026-102489.py [-h] -u URL [-c COMMAND] [--out-file OUT_FILE]
options:
-h, --help show this help message and exit
-u URL, --url URL The base URL of the target
-c COMMAND, --command COMMAND
Command to execute on the target
--out-file OUT_FILE Output file path on the target (default:
/tmp/zammad_rce.txt)
Run with the default id command:
python3 CVE-2026-102489.py -u http://zammad.example.com
Execute an arbitrary command:
python3 CVE-2026-102489.py -u http://zammad.example.com -c 'id'
Note: The information disclosure requires at least one authenticated user to be connected to the WebSocket endpoint at the time of exploitation.
"This software has been created purely for the purposes of academic research and for the development of effective defensive techniques, and is not intended to be used to attack systems except where explicitly authorized." Project maintainers assume no liability for misuse. Use responsibly.