Two severe zero-day vulnerabilities in Zammad—the open-source helpdesk software—have been confirmed to allow attackers to hijack sessions, execute code remotely as the Zammad user, and escalate privileges to root. These issues were exploited against the Dutch Institute for Vulnerability Disclosure (DIVD) in September 2026, as detailed in their case ID DIVD-2026-00015. The vulnerabilities are identified as CVE-2026-102489 and CVE-2026-102490.
What the Flaws Are
The first flaw, CVE-2026-102489, is a session-hijacking defect present in Zammad versions 6.3.0 through 6.5.4. It also exists in versions 7.0.0 through 7.1.3, though those later versions lack certain environmental conditions required for exploitation. Upon successful exploitation, this bug enables remote code execution under the Zammad service account.
The second flaw, CVE-2026-102490, allows users who already have access as the Zammad service account (locally on the server) to escalate privileges to root. This affects every release from Zammad version 1.5.0 through 7.1.0-alpha.
Attack Chain and Impact
These two flaws combine into a potent attack sequence: an external threat actor exploits CVE-2026-102489 to gain initial access and run commands as the Zammad user. Then they pivot via CVE-2026-102490 to gain root privileges. Full control over the server could follow—including altering support tickets, accessing attachments, modifying user accounts, planting persistent backdoors, and advancing laterally across networks.
The DIVD team discovered signs of exploitation on September 21, 2026. They conducted reproduction testing between September 22 and 23, then reported their findings to Zammad on September 24. By September 26, they were scanning for internet-facing instances of Zammad affected by these flaws and notifying operators.
What Administrators Should Do Now
Owners of Zammad instances are urged to treat this as an emergency incident. The only safe route is to update to the latest stable release—version 7—or otherwise take vulnerable servers offline until patches are fully verified. Note that even current alpha builds under version 7 are impacted by the privilege escalation issue.
Teams should also audit logs closely for evidence of session hijacking, strange admin behavior, unexpected command execution, or any modifications tied to the Zammad account. DIVD has published a log-check script to help identify signs of compromise. If any malicious activity is found, immediate isolation, credential rotation, service review, and full forensic analysis are warranted to uncover possible persistence.
Because there’s proof the vulnerabilities had been exploited before being publicly disclosed, simply applying patches may not eliminate all risks. Threat actors may already have established backdoors or hidden access.
The emergence of these flaws in Zammad underscores a persistent trend: even mature open-source platforms can harbor undiscovered critical weaknesses. Organizations depending on them must not just patch quickly, but also practice proactive response—continuous monitoring and preparing for the possibility that a breach occurred before a fix was available.