GBHackers

Zammad Vulnerabilities Let Attackers Execute Code and Escalate Privileges to Root


Two critical vulnerabilities in the open-source Zammad helpdesk and ticketing platform can be exploited together, enabling attackers to achieve remote code execution and gain root-level control of affected servers.

The Dutch Institute for Vulnerability Disclosure (DIVD) and Merlon Security discovered these vulnerabilities, tracked as CVE-2026-102489 and CVE-2026-102490, during an investigation into a breach of DIVD’s own infrastructure.

Zammad Vulnerabilities

In their advisory, DIVD-2026-00015, they describe an attack chain that starts with a session-hijacking issue in Zammad and culminates in local privilege escalation to root.

These vulnerabilities were reportedly used in an intrusion against DIVD on September 21, 2026, allowing attackers to compromise the Zammad service account, access additional services, and potentially read or exfiltrate sensitive information. DIVD noted that the full attack took only seconds, attributing the speed to an agentic, AI-powered attack workflow.

CVE-2026-102489 affects Zammad versions 6.3.0 through 6.5.4. This flaw enables session hijacking that can lead to remote code execution under the Zammad system user context.

An attacker who obtains or exploits a valid session can execute commands on the host using the permissions assigned to the Zammad service account.

This creates a critical initial access path since the Zammad account has access to application files, databases, logs, secrets, and internal services necessary for ticketing operations.

DIVD says the same vulnerable code exists in Zammad versions 7.0.0 through 7.1.3. However, the organization stated that the issue is not exploitable in those versions due to specific environmental conditions.

Zammad said exploitation is limited to older installations (6.5 and earlier) because of their runtime environment, and that mitigations for the affected code are included in Zammad version 7.2.0.

However, organizations should not interpret this as a reason to delay upgrades, as exposed legacy Zammad installations remain a serious concern.

The second issue, CVE-2026-102490, is a local privilege escalation vulnerability affecting Zammad versions 1.5.0 through 7.1.0-alpha, including the latest alpha builds mentioned in DIVD’s disclosure.

Once an attacker gains command execution as the local Zammad user, through CVE-2026-102489, stolen credentials, a malicious plugin, or other server-side weaknesses, they can elevate their privileges to root.

This turns an application compromise into a full operating system compromise, enabling actions such as installing persistence mechanisms, tampering with logs, accessing other local user data, and pivoting into connected infrastructure.

Together, these vulnerabilities are particularly dangerous. CVE-2026-102489 provides remote access to vulnerable 6.x systems, while CVE-2026-102490 eliminates the privilege boundary that would normally contain the compromise. Both issues have a CVSS score of 9.4 in the chained-attack scenario.

DIVD recommends that all Zammad users upgrade to version 7 or take affected instances offline. Administrators running Zammad versions 6.3.0–6.5.4 should treat the situation as urgent.

They should preserve application, web server, authentication, and system logs before remediation, restrict public access, rotate potentially exposed credentials, and investigate any unauthorized session activity and command execution.

DIVD has also published an IoC log-check script for CVE-2026-102489 and is actively scanning for vulnerable public instances, notifying affected owners.

This report outlines the incidents related to Zammad vulnerabilities CVE-2026-102489 and CVE-2026-102490, including indicators of compromise, affected versions, and mitigation guidance.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link