Two exploited flaws affect Zammad, the open-source helpdesk. CVE-2026-102489 hijacks a session and runs code as the Zammad user, and CVE-2026-102490 then escalates from that user to root. CISA added both to its Known Exploited Vulnerabilities (KEV) catalog on 2 October 2026.
As of the advisory Zammad published on 5 October, there is no fix for the root escalation, CVE-2026-102490.
The vendor and the discoverer disagree on the details. Zammad says CVE-2026-102489 can only be exploited on 6.5 and earlier and 7.0 and later are not practically affected, and assesses CVE-2026-102490 as not exploitable remotely on its own: an attacker must already have access to the server. The scores differ too: NVD (NIST) rates both CVSS v3.1 9.8 (network, no authentication), while the discoverer DIVD rates CVE-2026-102490 alone at v4.0 8.5 (HIGH, local) and only the chain with CVE-2026-102489 at 9.4 (CRITICAL). The score shown in this article is DIVD's standalone rating for CVE-2026-102490 (8.5). The disagreements are kept visible.
What to do now
- ✓First check which Zammad version you run. Zammad says if you are on 6.5 or earlier, update now. 6.5 and earlier are out of support and receive no security fixes.
- ✓Update to Zammad 7.2.0, the current stable release. The CVE-2026-102489 code was hardened in 7.2.0 (released 23 September 2026). Zammad says 7.0 and later are not practically affected, but the hardening is in 7.2.0.
- ✓Restrict access to the server to trusted administrators only. In Zammad's assessment CVE-2026-102490 requires the attacker to already have access to the server. Review SSH, administrator accounts and the privileges of other services on the same host.
- ✓Keep watching for the CVE-2026-102490 fix. It will be announced in Zammad's GitHub security advisories. Zammad says it is treating it as a top priority.
- ✓★If you exposed 6.5 or earlier, check for signs of compromise even after updating. Updating does not remove a breach. DIVD, the discoverer, advises all Zammad users to upgrade to version 7 or take it offline (DIVD case page).
- ✓DIVD has published a log-check script. It looks for traces of CVE-2026-102489 (session material in error output) in `/var/log/zammad` and `/var/log/nginx`. It is DIVD's guidance, not a Zammad procedure. On reading it, this site found that it only searches and prints logs with `zgrep`, with no commands that modify files or send data out. Still, read it yourself before running it on a production server. Even if it reports no indicators, DIVD says to also look for other signs such as unfamiliar processes and files
What happened, with dates
- ▸August 2026: According to Zammad's statement, it first received a report about CVE-2026-102489 this month and analysed it then
- ▸23 September 2026: Zammad 7.2.0 was released, including hardening of the CVE-2026-102489 code
- ▸21 September: DIVD's timeline says its own organisation was breached by abusing this vulnerability on this date (it announced the breach on 24 September)
- ▸24 September: DIVD reported the flaws to Zammad
- ▸26 September: DIVD scanned publicly reachable Zammad instances, made a limited disclosure and began notifying owners. Zammad objects that a CVE was published before it had received the details and that exploitation is being discussed publicly
- ▸29 September: Publication date of DIVD's CVE records
- ▸30 September: CVE-2026-102489 and CVE-2026-102490 appeared in NVD. DIVD also said the intrusion used a chain of two Zammad zero-days
- ▸1 October: Zammad issued a statement and said later that day it had received the technical details of CVE-2026-102490 from DIVD
- ▸★2 October: CISA added both to KEV. The due date is 5 October (a deadline for US federal agencies)
- ▸5 October: Zammad published its formal security advisory
How the two flaws relate
- ▸CVE-2026-102489 (session fixation to code execution): lets an attacker hijack a session and run code as the Zammad user. NVD says "6.3.0 to 6.5.4 are vulnerable; 7.0.0 to 7.1.3 also contain it but it is not exploitable because of environment conditions". DIVD's CVE record also marks 7.0.0 and later as unaffected
- ▸CVE-2026-102490 (local privilege escalation): lets the Zammad user escalate to root. NVD says "all versions including the latest alpha"
- ▸The two chain together. CISA's KEV text says each can be chained with the other: get in with the first, take root with the second
- ▸So on 6.5 and earlier, root may be reachable remotely. On 7.0 and later, Zammad's assessment is that the way in (CVE-2026-102489) is practically unusable, and CVE-2026-102490 matters only to someone who is already on the server
Affected versions: the sources disagree
The scope of CVE-2026-102490 differs by source. Here are the statements as I found them.
- ▸NVD description: "all versions of Zammad, including the latest alpha"
- ▸NVD affected-version configuration (CPE): 1.5.0 up to but excluding 7.1.0, plus the 7.1.0 alpha
- ▸DIVD's CVE record: 1.5.0 up to but excluding 7.1.0-alpha (the title says "v1.5.0 to v7.1.0-alpha" and the description says "all versions including the latest alpha")
- ▸Zammad: "cannot confirm the vulnerability, its scope or the affected versions at this time" (1 October statement). In the 5 October advisory: "this issue is related to a confirmed vulnerability in packager.io, and our team is working on a solution"
- ▸So it cannot be stated from these sources whether current 7.1.x or 7.2.0 are affected by CVE-2026-102490. Until a fix ships, assume you are affected and restrict server access
What is known and unknown about exploitation
Known. CISA added both to KEV on 2 October (ransomware use is listed as "Unknown"). DIVD says its own organisation was breached through a chain of these two flaws. DIVD (case DIVD-2026-00014, statement of 30 September) says the attack chained these two zero-days. It assesses from the method that it was an AI-agent attack and writes that session hijacking, code execution and escalation from the Zammad user to root happened in seconds. Network segmentation and its response after detection stopped the attacker going deeper, but DIVD disclosed on 1 October that data such as volunteers' email addresses got out.
Unknown. Zammad's 1 October statement only says some sites describe CVE-2026-102490 as exploited, so Zammad's official material does not say it has confirmed exploitation itself. There is no source I can check for the scale of damage elsewhere or the details of the techniques used.
Where the vendor and DIVD differ
Zammad strongly objects to how the disclosure was handled. Its statement says it was told on 24 September, public scanning and disclosure followed on the 26th, and a CVE was published before it received details, leaving administrators without the information to act. Zammad says it does not consider this responsible disclosure.
This article does not decide who is right. What affects readers is that no fix exists yet while CISA treats the flaw as exploited.
What could not be confirmed
- ▸Exploitation details and indicators of compromise for the escalation itself (CVE-2026-102490). DIVD's script looks for traces of CVE-2026-102489; I found no procedure for detecting the root escalation (CVE-2026-102490) in Zammad's or DIVD's published material. The scale of damage at other organisations also cannot be checked
- ▸How the CVSS ratings differ. NVD rates both v3.1 9.8 (network, no authentication). DIVD rates CVE-2026-102490 alone at v4.0 8.5 (HIGH, local, low privileges) and 9.4 (CRITICAL) when chained, and CVE-2026-102489 alone at 8.7 (HIGH) and 9.4 (CRITICAL) when chained. Zammad calls CVE-2026-102490 a local flaw. This article shows DIVD's standalone rating for CVE-2026-102490 (8.5)
- ▸Whether every version of 6.5 and earlier is exploitable through CVE-2026-102489. NVD says "6.3.0 to 6.5.4"; Zammad says "6.5 and earlier"
- ▸Whether you were already targeted. DIVD's script only finds leaked session material. Checking for unusual processes and files and for changes to administrators or API tokens is this site's general advice, not a Zammad procedure
Three lines to share
- ▸Two Zammad helpdesk flaws (CVE-2026-102489 and CVE-2026-102490) are in CISA's KEV list as a chain used in a real intrusion. The root escalation has no fix yet
- ▸★If you run Zammad 6.5 or earlier, update now (it is out of support). Target 7.2.0. Even on 7.x, restrict server access to trusted administrators
- ▸The fix will be announced in Zammad's GitHub security advisories. Until then, review server privileges and wait
Sources
- Zammad: Security Advisory CVE-2026-102489 and CVE-2026-102490 (5 October 2026; the vendor's assessment, recommendations and fix status)↗
- Zammad Community: Take care: Local Privilege Escalation (CVE-2026-102490) is reported as being actively exploited (1 October; Zammad's statement and DIVD's description)↗
- Zammad: release list (7.2.0 on 23 September 2026, 7.1.3 on 25 August)↗
- DIVD CSIRT: DIVD-2026-00015 (the case that reported the two Zammad flaws)↗
- CISA: Known Exploited Vulnerabilities catalog (CVE-2026-102490, added 2 October 2026)↗
- CISA: Known Exploited Vulnerabilities catalog (CVE-2026-102489, added 2 October 2026)↗
- NVD: CVE-2026-102490 (NIST CVSS v3.1 9.8 and the affected-version records)↗
- NVD: CVE-2026-102489↗
- DIVD CSIRT: DIVD-2026-00014 (the account of DIVD's own breach; statements from 24 September to 1 October)↗
- DIVD CSIRT: log-check script cve-2026-102489_ioc_check_script_v2.sh (checks for traces of CVE-2026-102489; read it before running)↗
- GitHub: zammad/zammad security advisories (where the LPE fix will be announced)↗
