VDB

GCVE-110-NCSC-2026-396

GCVE-110-NCSC-2026-396
Advisory Published
Vulnetix · Advisory published September 30, 2026
Zammad versions 6.3.0 to 6.5.4 have a session hijack vulnerability enabling remote code execution as the zammad user, while versions 7.0.0 to 7.1.3 contain the vulnerability but it is not exploitable due to environmental factors.

Affected Products

VendorProductVersionsPlatforms
Zammad GmbHvers:unknown/*——

References

advisory
advisory
advisory
advisory

Browse GCVE Records

3,105 records in the GCVE database · Updated October 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›