Public PoC released for CVE-2026-102489, a critical Zammad flaw enabling unauthenticated session cookie theft and potential code execution.