Zammad Zero-Day Vulnerabilities Exploited

Two Zammad zero-day vulnerabilities give attackers root on helpdesk servers. Used against DIVD, on CISA KEV, one flaw had no fix at disclosure.

Two Zammad zero-day vulnerabilities, CVE-2026-102489 and CVE-2026-102490, let an attacker take over the open-source helpdesk and reach root on its server. The Dutch Institute for Vulnerability Disclosure (DIVD) says an automated AI agent chained them against its own network on September 21. CISA has added the first flaw to its Known Exploited Vulnerabilities catalog, and the root escalation had no fix at disclosure.

What Happened

The Zammad zero-day vulnerabilities work as a pair. CVE-2026-102489 is a session hijack flaw (CWE-384, session fixation) that leads to remote code execution as the zammad system user. It is exploitable in Zammad 6.3.0 through 6.5.4. The same code is present in 7.0.0 through 7.1.3 but, according to DIVD, cannot be exploited there because of environment conditions. CVE-2026-102490 lets the low-privilege zammad user escalate to root, and DIVD says it affects all Zammad versions, including the latest alpha. The CVE record for CVE-2026-102489 carries two CVSS v4.0 scores, 8.7 and 9.4; the higher one rates the impact on connected systems as high.

DIVD, a volunteer-run nonprofit that warns owners of vulnerable systems, says the attacker first got in on September 21 and was detected the next day. DIVD went public on September 24 and published the CVEs on September 30, after working out with Merlon Security that the way in was two unknown flaws in its own Zammad helpdesk. According to DIVD, the agent hijacked sessions, ran code and reached root within seconds, then read and exfiltrated data from other services. Network segmentation and a fast response kept it from going deeper, but DIVD still assumes breach and has not yet said which data was taken.

The AI-agent description comes from DIVD itself, which is both the victim and the CVE assigning authority. We have seen no independent confirmation and no published logs. The exploitation is independently visible: CISA added CVE-2026-102489 to the KEV catalog on October 2 with a federal remediation due date of October 5, according to the CISA catalog.

Why It Matters

A helpdesk server holds customer email, ticket history, attachments and the credentials it uses to fetch and send mail. Root on that host means an attacker can read all of it and write to customers from a trusted support address, with real ticket context as bait. Zammad GmbH is a German vendor. If personal data was reachable, a GDPR breach assessment and, for NIS2 entities, incident-reporting duties may apply. Involve your data protection officer and legal counsel early.

The agent angle shortens the response window. A chain that goes from session hijack to code execution to root in seconds leaves no room for a human to react, so the only controls that count are the ones already in place: exposure, segmentation, logging. We covered the first documented AI-run ransomware attack, JADEPUFFER, in July.

What You Should Do Now

  1. Find every Zammad instance, including forgotten test and internal ones, and check its version. Anything from 6.3.0 to 6.5.4 is exploitable per DIVD.
  2. Copy the application and web server logs off the host first. Later forensic work may need them. Then upgrade to Zammad 7 or later, or take the instance offline. Upgrading closes the entry point for CVE-2026-102489; DIVD lists no fix for the root escalation CVE-2026-102490 at disclosure, so treat the host as one flaw away from root.
  3. Review your Zammad application and web server logs for unusual session or login activity since September 21, and check DIVD’s case page for any published indicators. A clean result is not proof of safety: logs that were already rotated away cannot be checked.
  4. If anything matches, assume root. Rebuild the host and rotate every credential it held, starting with the mailbox passwords and OAuth grants behind its email channels and any API tokens. Then decide whether personal data was affected.
  5. Cut exposure: restrict Zammad to a VPN or an IP allowlist if agents do not need it from the open internet, and keep it in a network segment that cannot reach other servers. Watch Zammad’s GitHub security advisories for the fix to CVE-2026-102490.

DIESEC Perspective

Helpdesk systems rarely appear on asset lists as security-critical, yet they combine customer data, mail credentials and a trusted sender identity. At DIVD, how far the compromised host could reach decided how bad the damage got.

Not sure whether your helpdesk or ticketing system is reachable from the internet, or whether your Zammad logs show these indicators? Contact DIESEC for a rapid exposure assessment and compromise check.

Sources: DIVD case DIVD-2026-00015 | NVD CVE-2026-102489 | BleepingComputer | Help Net Security
Published: 2026-10-06 | Category: AI Security | ~5 min read