The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added two severe vulnerabilities in the Zammad helpdesk platform to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. These flaws—CVE-2026-102489 and CVE-2026-102490—allow attackers to chain attacks spanning remote access and privilege elevation, potentially enabling full server control. Zammad is an open-source ticketing system used widely for customer support, internal help desks, and service requests. Zammad servers often hold sensitive data such as credentials, emails, and support logs, meaning any compromise could carry serious risk. DIVD refers to the Dutch Institute for Vulnerability Disclosure, which played a key role in discovering and reporting the issues.
The Vulnerabilities Explained
CVE-2026-102489 is a session fixation vulnerability found in older Zammad installs. It enables an attacker to force or trick a victim into using a pre-known session token, which then allows remote code execution under a user account with minimal privileges. CVE-2026-102490 is an improper privilege management flaw. It allows a local, less privileged Zammad user to elevate to root level—a full administrative account in Linux environments. When combined with the session fixation vulnerability, the chain could allow a remote attacker to move from low-level access all the way to full server compromise.
Vendor & Agency Response
CISA added these two vulnerabilities to its catalog on October 2, 2026, and issued a remediation deadline of October 5 for federal civilian agencies. Under Binding Operational Directive 26-04, agencies must conduct forensic analysis for signs of past compromise, not just apply patches or mitigations. As of October 5, 2026, that deadline is in effect.
Zammad has acknowledged the report associated with DIVD case DIVD-2026-00015. The vendor clarified that CVE-2026-102489 affects only version 6.5 and earlier, all of which are now out of support. Versions 7.0 and higher are considered safe in practice, with version 7.2.0 introducing extra hardening. Regarding CVE-2026-102490, Zammad initially noted it had not received full technical details and was unsure about the claims. A later update confirmed that the privilege escalation issue, when isolated, requires local server access; it cannot be exploited remotely by itself. Administrators running Zammad version 6.5 or older are strongly urged to upgrade to 7.2.0 or later.
What Organizations Should Do
Operators of Zammad servers should immediately check logs, running processes, user accounts, scheduled tasks, SSH access, web server logs, and outbound connections for any indicators of unauthorized activity. CISA also advises reviewing how exposed affected systems are to the internet and applying all available mitigations. If systems can’t be secured—or if organizations can’t apply mitigation steps effectively—they should consider discontinuing use of the vulnerable version.
This case underscores how combining multiple modest flaws can yield a serious breach. One vulnerability gives attackers remote foothold; the other lets them escalate privileges. The danger is not always in a single bug, but the path built by linking them together.
Why it matters: The fact that these vulnerabilities are under active exploitation makes prompt patching essential. Entities running outdated or unsupported Zammad versions are at particular risk. What to watch: movement toward Zammad 7.2.0 in organizations, evidence of exploitation in incident response reports, and whether similar chained vulnerabilities are being uncovered elsewhere in helpdesk and ticketing platforms.