CVE-2026-102489: Zammad session flaw chained to root, due 5 October
Zammad helpdesk session fixation and local root escalation

CVE-2026-102489: Zammad session flaw chained to root, due 5 October

Two Zammad helpdesk flaws are on CISA's Known Exploited Vulnerabilities list, and the federal due date is today, 5 October 2026. Chained, they turn a remote session bug into root on the host.

What happened

CVE-2026-102489 is a session fixation issue. On Zammad 6.3.0 through 6.5.4 it can lead to remote code execution as the local zammad user. The defect is also present from 7.0.0 through 7.1.3, but the CVE record says it is not exploitable there because of environment conditions. NVD scores it CVSS 3.1 at 9.8.

CVE-2026-102490 is improper privilege management. It lets the local zammad user escalate to root. It does not work remotely on its own. CISA says the two can be chained, and added both on 2 October 2026. Binding Operational Directive 26-04 also calls for forensic triage, not a patch-and-forget.

The Dutch Institute for Vulnerability Disclosure assigned the CVEs after attackers hit DIVD's own Zammad. Zammad has said the session bug is practically exploitable only on 6.5 and earlier, which are out of support, and that 7.2.0 added hardening. The vendor later confirmed it received the privilege-escalation details from DIVD.

Who is affected

  • Zammad 6.5 and older on Linux or Docker, especially if the helpdesk is reachable from the internet.
  • Hosts where the zammad system account exists, because that is the bridge to root via CVE-2026-102490.
  • Supported 7.x installs are in better shape for the session bug, but 7.2.0 is the release the vendor points to for the extra hardening.

What to do now

Move any Zammad 6.5 or older to 7.2.0 today, and review the host for unexpected root activity even if you are already on 7.x. Check web logs, SSH access, new local accounts, scheduled tasks, and outbound connections. If you cannot patch an exposed 6.x box, take it off the internet. CISA's fallback is to stop using the product when mitigations are not available.

Source: Cyber Security News, with dates and scores checked against the NVD KEV entry. CISA warns of Zammad DIVD vulnerabilities actively exploited in attacks. Records: CVE-2026-102489 and CVE-2026-102490.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

Google OSS VRP paused 1 October after AI bug-report flood
Google open source vulnerability rewards program AI submissions pause