Zammad Helpdesk Zero-Day Chain: Session Hijack to RCE, Then Root (CVE-2026-102489 / CVE-2026-102490, CISA KEV)

Zammad Helpdesk Zero-Day Chain (CVE-2026-102489 / CVE-2026-102490) KEV

On 2 October 2026, CISA added two Zammad vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-102489, a session fixation flaw that CISA says can lead to remote code execution as the zammad user, and CVE-2026-102490, an improper privilege management flaw that CISA says can let the local zammad user escalate to root. CISA notes each can be chained with the other. The federal (FCEB) due date is 5 October 2026. NVD scores each at CVSS 3.1 9.8 Critical.

Both CVEs were assigned by the Dutch Institute for Vulnerability Disclosure (DIVD), acting as CNA, after DIVD says attackers first accessed its own systems on 21 September 2026 by abusing Zammad vulnerabilities. DIVD describes the intrusion as an agentic-AI-driven attack and says the two flaws were chained against it.

This is a disputed disclosure. Zammad GmbH has publicly disagreed with DIVD on affected versions, on exploitability of CVE-2026-102490 on its own, and on how the disclosure was handled. As of 5 October 2026, no formal Zammad security advisory or GitHub Security Advisory exists for either CVE, and no source confirms a vendor fix for CVE-2026-102490. This advisory sets out each party's position with attribution rather than picking a side.

Zammad is an open-source customer-support and IT helpdesk ticketing platform, available self-hosted (Linux / Docker) or as a service hosted by Zammad GmbH (per BleepingComputer, 30 September 2026).

Technical Information

CVE-2026-102489: session fixation leading to RCE as the zammad user

  • CISA KEV name: Zammad GmbH Zammad Session Fixation Vulnerability. CISA's description: a session fixation vulnerability "that can lead to remote code execution as the zammad user," which "can be chained with CVE-2026-102490."
  • CWE: CWE-384 Session Fixation (NVD primary and CISA-ADP).
  • NVD CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
  • DIVD CVSS 4.0: 8.7 High standalone (network) on DIVD's CVE page; 9.4 Critical for DIVD's chained scenario, which is the CNA score carried in the NVD record.
  • CISA SSVC (ADP): exploitation active; automatable yes; technical impact total.

What DIVD says: "Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions."

What Zammad says (community forum statement, 1 October 2026, 12:16 UTC): "Exploitation is only possible on Zammad 6.5 and older, because of the runtime environment those versions use… Zammad 7.0 and later are not affected." Zammad adds that it has "still hardened the affected code" and that "the change is included in Zammad 7.2.0." Zammad also says it "first received a report about this issue in August 2026"; DIVD's timeline dates its report to Zammad to 24 September 2026. Whether these refer to the same finding is not established.

CVE-2026-102490: local privilege escalation from zammad to root

  • CISA KEV name: Zammad GmbH Zammad Improper Privilege Management Vulnerability. CISA's description: a flaw "that can allow the local zammad user to escalate privileges to root," which "can be chained with CVE-2026-102489."
  • CWE: CWE-269 Improper Privilege Management (CISA-ADP).
  • NVD CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). This network / no-privilege vector sits awkwardly with the "local" description; NVD kept 9.8 after analysis on 3 October 2026.
  • DIVD CVSS 4.0: 8.5 High standalone (AV:L/PR:L) on DIVD's CVE page; 9.4 Critical chained.
  • CISA SSVC (ADP): exploitation active; automatable no; technical impact total.

What DIVD says: "In all versions of Zammad including the latest alpha has an vulnerability which enables the local zammad user to escalate privileges to root," with a stated range of v1.5.0 to v7.1.0-alpha.

What Zammad says: At 12:16 UTC on 1 October, Zammad said DIVD had not given it technical details and that it "cannot confirm the vulnerability, its scope or the affected versions at this time." At 19:48 UTC the same day, after receiving details from DIVD, Zammad said: "This issue cannot be exploited remotely on its own. An attacker would already need access to your server." Zammad said it is working on it and pointed users to its GitHub Security Advisories for updates. None had been published as of 5 October 2026.

The chain, as DIVD describes it

DIVD says the two flaws were used together in its breach: "Used together, they allowed the attackers to hijack sessions, run code remotely, and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack" (as quoted by BleepingComputer, 30 September 2026). DIVD reports that attackers then reached other services and exfiltrated volunteer data, including DIVD email addresses and possibly contact details, and that network segmentation stopped them going deeper. The breach account and the AI-agent narrative come from DIVD alone. DIVD has said it sees no link to any known public threat actor.

Zammad does not dispute that the privilege escalation needs prior access and does not directly address DIVD's breach account.

The disclosure dispute

  • DIVD timeline: breach 21 September; reported to Zammad 24 September; on 26 September DIVD "scanned for publicly available and vulnerable Zammad instances," "created a limited disclosure for CVE-2026-102489 & CVE-2026-102490," and began notifying owners. DIVD's CVE pages were published 29 September; NVD published both CVEs 30 September.
  • Zammad position: "DIVD's own timeline shows a report to us on 24 September 2026, followed by public scanning and disclosure on 26 September 2026. A CVE identifier was published for a vulnerability we had not been told about… We do not consider this a responsible way to handle vulnerabilities."
  • Independent context: Severity Daily (2–3 October 2026) notes that DIVD is both CNA and breach victim, calls the two-day gap atypical, and observes that DIVD held the report while responding to an active intrusion of its own.

Zammad's statements are community forum posts, not a formal security advisory.

Affected Product Versions

Sources conflict. Each range below is attributed; none is presented as settled.

CVE DIVD case page DIVD CVE record (CNA) NVD CPE configuration Zammad
CVE-2026-102489 6.3.0 to 6.5.4 exploitable; present but "not exploitable" in 7.0.0–7.1.3 Affected from 6.3.0 up to (not including) 6.5.4; 7.0.0 and later unaffected Vulnerable from 6.3.0 up to (not including) 6.5.4, and 7.0.0 through 7.1.3 "Zammad 6.5 and older" exploitable; "7.0 and later are not affected"; hardening in 7.2.0
CVE-2026-102490 v1.5.0 to v7.1.0-alpha; prose says "all versions… including the latest alpha" Affected from 1.5.0 up to (not including) 7.1.0-alpha Vulnerable from 1.5.0 up to (not including) 7.1.0, plus 7.1.0-alpha No vendor version list; "cannot be exploited remotely on its own"

Points of conflict to be aware of:

  • 6.5.4 and CVE-2026-102489: DIVD's prose reads 6.3.0 to 6.5.4 inclusive; the structured CNA and NVD data stop below 6.5.4. Zammad says 6.5 and older are exploitable. Version 6.5 and older are end of support per Zammad, so 6.5.4 should be treated as exposed regardless.
  • 7.0.0–7.1.3 and CVE-2026-102489: DIVD says present but not exploitable; Zammad and the DIVD CVE record say unaffected; NVD's CPE marks the range vulnerable.
  • CVE-2026-102490 on current releases: no source states whether Zammad 7.1.x stable or 7.2.0 is affected. By DIVD's stated range, 7.0.x falls inside the affected range.
  • End of support: Zammad says 6.5 and older "reached end of support some time ago" and that security fixes go only to the current stable release.
  • Zammad-hosted (SaaS): no primary source from Zammad or DIVD states whether Zammad-hosted tenants were affected or have been remediated.

Workaround and Mitigation

There is no confirmed vendor fix for CVE-2026-102490 as of 5 October 2026. Zammad 7.2.0 (released 23 September 2026, one day before DIVD's report; its release notes mention neither CVE) is the vendor's recommendation, and Zammad says it includes the hardening for CVE-2026-102489. runZero reported on 2 October 2026 that there was no official patch for CVE-2026-102490. Each party's guidance is attributed below.

  1. Upgrade (Zammad's guidance): "Update to Zammad 7.2.0, the current stable release. If you still run Zammad 6.5 or older, update now. These versions no longer receive security fixes."
  2. Upgrade or take offline (DIVD's guidance): "We advise all users of Zammad to upgrade to version 7 of Zammad or to take it offline." DIVD's own range for CVE-2026-102490 includes 7.0.x, so moving to "version 7" alone may not clear that CVE; 7.2.0 sits above DIVD's stated range, but no source confirms it is fixed.
  3. CISA KEV required action: apply mitigations per vendor instructions in line with CISA BOD 26-04 and CISA's forensics triage requirements, or "discontinue use of the product if mitigations are unavailable." KEV marks forensic triage as required for both entries.
  4. Forensic triage: DIVD publishes a log-check script that searches Zammad and nginx logs for CVE-2026-102489-related session-material indicators. DIVD also advises looking for unfamiliar processes and files. Review the script before running it in your environment.
  5. Reduce exposure: inventory every Zammad instance, confirm whether it is internet-facing, and prioritise anything on 6.3.0–6.5.4 or older.
  6. Watch for the vendor advisory: monitor Zammad's GitHub Security Advisories for a CVE-2026-102490 fix.

Indicators of Compromise

No atomic IoCs (IP addresses, domains, file hashes or URLs) have been published by DIVD, CISA or Zammad as of 5 October 2026.

The only published detection aid is behavioural: DIVD's log-check script (linked above) looks for session-material indicators in Zammad and nginx logs, and DIVD advises checking for unfamiliar processes and files. DIVD's redacted log screenshots from 26 September are not IoC-grade.

No source maps this activity to MITRE ATT&CK techniques, and no threat actor is named. CISA lists known ransomware campaign use as Unknown.

Why this matters for third-party / vendor risk

A helpdesk is where your vendors keep your tickets: customer PII, support correspondence, attachments and internal IT requests. DIVD's own account shows a compromised Zammad instance becoming a pivot to other services and a route to data exfiltration, so any supplier or subprocessor running Zammad, especially self-hosted on 6.5 or older and exposed to the internet, is a live third-party exposure while a fix for CVE-2026-102490 remains unconfirmed.

Book a demo to see which of your vendors run exposed Zammad instances.

Forwardable blurb for your TPRM / vendor-risk owner:

"Please confirm whether you or any subprocessor handling our data run Zammad, self-hosted or Zammad-hosted. If so: the exact version, whether it is internet-facing, whether it has been upgraded to 7.2.0 or taken offline and when, whether you received a DIVD notification (sent from 26 September 2026), whether you ran DIVD's log-check script or other forensic triage for CVE-2026-102489 / CVE-2026-102490 and with what result, and whether you have any evidence that ticket data was accessed."

Sources

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.