Zammad vulnerabilities: CVE-2026-102489 and CVE-2026-102490 #
While investigating a separate incident (DIVD-2026-00014), the Dutch Institute for Vulnerability Disclosure (DIVD) identified (DIVD-2026-00015) two vulnerabilities in Zammad:
- CVE-2026-102489: A session hijacking vulnerability classified under CWE-384 (Session Fixation) that allows aremote attacker to hijack a Zammad user's session, potentially leading to remote code execution (RCE) under the context of the local zammad user. The vulnerability has been designated CVE-2026-102489 and has been rated high with a CVSS score of 8.7.
- CVE-2026-102490: A local privilege escalation vulnerability enabling the local zammad user to escalate privileges to root. The vulnerability has been designated CVE-2026-102490 and has been rated high with a CVSS score of 8.5.
Evidence indicates that CVE-2026-102489 and CVE-2026-102490 are actively exploited in the wild, leading to their addition to the CISA Known Exploited Vulnerabilities (KEV) catalog on October 2, 2026.
The following versions are affected
- Zammad: Versions 1.5.0 through 7.1.0-alpha.
Exploitability Notes:
- CVE-2026-102489: Directly affects versions 6.3.0 through 6.5.4. Versions 7.0.0 through 7.1.3 contain the underlying code flaw but are not exploitable in practice due to runtime environment conditions on those releases.
- CVE-2026-102490: Reported to affect versions 1.5.0 through 7.1.0-alpha. The vendor disputes this report, stating it has not received technical details from DIVD to confirm the flaw, its scope, or affected releases.
What is Zammad? #
Zammad is an open source help desk and ticketing system that organizations self-host to manage customer support requests across email, chat, and social channels.
What is the impact? #
Successful exploitation of these vulnerabilities would allow an unauthenticated remote attacker to compromise user sessions and potentially achieve complete root-level takeover of the host operating system.
Are any updates or workarounds available? #
Users are encouraged to update to the latest version as quickly as possible:
- Zammad: Upgrade to version 7.2.0 or later.
Remediation Notes:
- CVE-2026-102489: Version 7.2.0 includes security hardening to resolve this vulnerability.
- CVE-2026-102490: Zammad has not released an official patch as of this writing. Follow Zammad's security advisories (https://github.com/zammad/zamm...) for patch updates.
- End-of-Support (EOS) Systems: Versions 6.5 and earlier have reached end-of-support and no longer receive security fixes. Administrators should upgrade to a supported release regardless of specific exploitability metrics.
Finding exposed Zammad installations with runZero #
From the Service inventory, use the following query to locate potentially impacted installations:
_asset.protocol:=http AND protocol:=http AND favicon.ico.image.mmh3:="-1687285536"