CISA Lists Two Zammad Flaws as Exploited; the Root-Escalation Bug Has No Patch
Security / news
CISA Lists Two Zammad Flaws as Exploited; the Root-Escalation Bug Has No Patch
The Dutch Institute for Vulnerability Disclosure found CVE-2026-102489 and CVE-2026-102490 after attackers used them against its own systems.
An unauthenticated remote attacker can take over a session on a self-hosted Zammad 6.3.0 through 6.5.4 helpdesk, run code as the zammad user, then climb to root. The second step needs only local access to the host and has no patch.
CISA added both flaws, CVE-2026-102489 and CVE-2026-102490, to its Known Exploited Vulnerabilities catalog on Oct. 2 with a due date of Oct. 5, according to the catalog entries. That is a three-day window for federal civilian agencies, and the entries tell them to follow forensics triage requirements as well as apply vendor mitigations.
What each flaw lets an attacker do
CVE-2026-102489 is a session fixation bug (CWE-384). Zammad's own fix shipped in 7.2.0, according to runZero's write-up by software engineer and security researcher Matthew Kienow, which rates it 8.7 (high).
CVE-2026-102490 is an improper privilege management bug (CWE-269) that lets the local zammad user become root. runZero rates it 8.5 and lists affected versions as 1.5.0 through 7.1.0-alpha. It also reports that Zammad disputes the scope of the report and says it received insufficient technical detail.
Chained, the pair scores 9.4, Infosecurity Magazine reported. One outlet, Security Affairs, attached 9.4 to each flaw separately. The CISA entries carry no score, so the individual ratings above are runZero's.
| Flaw | Weakness | Score (runZero) | Patch as of Oct. 2 |
|---|---|---|---|
| CVE-2026-102489 | Session fixation, CWE-384 | 8.7 | Zammad 7.2.0 |
| CVE-2026-102490 | Privilege management, CWE-269 | 8.5 | None |
- CVE-2026-102490 alone8.5 CVSS
- CVE-2026-102489 alone8.7 CVSS
- Chained9.4 CVSS
Source: runZero (individual scores) and Infosecurity Magazine (chained score), accessed 2026-10-03
Which versions are exposed
The advice is not uniform across sources. runZero says CVE-2026-102489 is directly exploitable on 6.3.0 through 6.5.4, and that the underlying flaw also sits in 7.0.0 through 7.1.3 but is not practically exploitable there. Security Affairs lists both ranges as affected without that distinction.
DIVD, the Dutch Institute for Vulnerability Disclosure, tells operators to move to version 7 or take instances offline. Because CVE-2026-102490 has no fix, a patched 7.x install still depends on the initial foothold being closed.
runZero published a service-inventory query keyed on the Zammad favicon hash (-1687285536) for finding exposed instances.
How DIVD found them: it was breached
DIVD found the bugs after attackers used them against its own systems. Techtimes dates the breach to Sept. 21; DIVD disclosed it on Sept. 30, working with Merlon Security, BleepingComputer reported.
DIVD said the attackers could "hijack sessions, run code remotely and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack." Its logs showed scripts containing notes in which the agent justified its own actions, "explaining why what it's doing is okay and really not phishing, something a human attacker wouldn't bother with."
The institute lost volunteer email addresses, and contact details may be exposed, so staff impersonation is a risk. Network segmentation stopped the intruder moving further. The claim that an autonomous agent drove the intrusion rests on DIVD's reading of its own logs; no independent party has published an analysis of them.
What operators should do
Zammad says it has more than 2,000 customers and 55,000 users, including De'Longhi, Amnesty International and Nextcloud. Hosted customers depend on the vendor; self-hosters have to act.
Upgrade to 7.2.0, and treat any instance that was internet-facing before then as possibly compromised. That means checking for new sessions, unexpected processes owned by zammad, and root-owned changes. Zammad's release page is where a fix for CVE-2026-102490 will appear, and CISA's Oct. 5 deadline is the next date to watch.
This is the same pattern as the Citrix NetScaler zero-days and the FortiMail path-traversal flaw: exploitation was under way before a complete fix existed.
Sources
More in Security
- 01NetScaler CVE-2026-88779 Is Rated Denial of Service, but a Researcher Reports a Payload DownloadCitrix patched a SAML memory overflow on October 3 and 4 after attacks began. CISA gave agencies until October 7, and the appliances patched last week for CVE-2026-88771 through CVE-2026-88778 need updating again.
- 02Cisco SD-WAN Manager Flaw CVE-2026-76504 Needs One Encoded Character for Admin API Access, With No WorkaroundCisco's PSIRT found exploitation during a support case in September. Six release trains have fixes, and the vendor and two security firms count Cisco's earlier SD-WAN flaws differently.
- 03Two Zammad Zero-Days Took an Attacker From Session Hijack to Root at the Dutch Institute for Vulnerability DisclosureCISA put CVE-2026-102489 and CVE-2026-102490 in its exploited catalog on October 2. DIVD says an AI agent, not a person, ran the intrusion it found on its own ticketing system.
- 04Citrix NetScaler Zero-Days Are Exploited Without Credentials, and Web Shells Survive the PatchCVE-2026-88771 and CVE-2026-88772 both score 9.5. Citrix shipped fixed builds on September 27, but researchers say implants planted earlier persist through the update.