Zammad CVE-2026-102489: KEV due date is today
helpdesk session hijack chained to root

Zammad CVE-2026-102489: KEV due date is today

CISA added two Zammad flaws to the Known Exploited Vulnerabilities catalog on 2 October 2026 and set both due dates at 5 October. On unsupported 6.x builds they chain: a remote session bug becomes code execution as the zammad user, then a local privilege bug becomes root.

What happened

CVE-2026-102489 is a session-fixation flaw. Zammad versions 6.3.0 through 6.5.4 can be hijacked into remote code execution as the zammad account. The same code exists in 7.0.0 through 7.1.3, but Zammad and the Dutch Institute for Vulnerability Disclosure say it is not practically exploitable there.

CVE-2026-102490 is improper privilege management. A local zammad user can escalate to root. CISA says the two can be combined. DIVD says an autonomous agent used that chain against its own helpdesk on 21 September, reached root within seconds, and took volunteer contact data. Zammad's current hardening line is 7.2.0. The 6.x branches are out of security support.

Who is affected

Self-hosted Zammad, especially anything still on 6.5 or older and reachable from the network. A helpdesk usually holds mail credentials, API tokens, and the correspondence an attacker needs for the next phish. Cloud customers should follow the hoster's guidance rather than assuming the KEV line does not apply.

What to do now

  • Inventory every Zammad instance today. If it is 6.5 or older, move it to 7.2.0 and preserve logs before you rebuild.
  • Hunt for the zammad account spawning a shell, writing privileged files, or opening new outbound connections.
  • Rotate secrets that lived on that host: database passwords, mail credentials, API tokens, SSO client secrets.
  • Block east-west movement from the helpdesk VLAN. A ticket system should not be a jump host.

Source: GBHackers, 5 October 2026, citing the CISA KEV catalog. Read the report.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

Denmark CPR breach: 8.8 million identity records
company CPR access abused for ten days