zammad security advisories
4 threat alerts tracking vulnerabilities and security advisories that affect zammad products.
Vulnios monitors zammad CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent zammad security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2026-102489 — zammad, docker — zammad, docker
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3
criticalCVE-2026-102489Critical Vulnerability: CVE-2026-102490 — zammad, docker — zammad, docker
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
criticalCVE-2026-102490Critical Vulnerability: CVE-2017-5619 — zammad — zammad
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the valid password string
criticalCVE-2017-5619Critical Vulnerability: CVE-2017-6080 — zammad — zammad
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protection mechanism involving HTTP Access-Control headers. To exploit the vulnerability
criticalCVE-2017-6080
Track zammad exposure across your environment
Vulnios automatically cross-references your asset inventory against new zammad CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan