VDB
GCVE-110-NCSC-2026-396
GCVE-110-NCSC-2026-396
Advisory Published
Zammad versions 6.3.0 to 6.5.4 have a session hijack vulnerability enabling remote code execution as the zammad user, while versions 7.0.0 to 7.1.3 contain the vulnerability but it is not exploitable due to environmental factors.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Zammad GmbH | vers:unknown/* | — | — |
Browse GCVE Records
3,105 records in the GCVE database · Updated October 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.