News

Zammad Sessions Become Code Execution, Then Root

Louis Stowasser
Louis Stowasser
Friday 2 October 2026
Zammad Sessions Become Code Execution, Then Root
Zammad Sessions Become Code Execution, Then Root

CVE-2026-102489 is an unauthenticated session-fixation flaw in Zammad, the open-source web helpdesk used to handle customer support, internal IT tickets, HR requests and other casework. That makes the exposure broader than a typical support portal: a Zammad server often sits at the edge of an organisation, accepts email and web requests, and holds ticket histories, attachments, user data and integrations.

Session fixation means an attacker can arrange for a victim to use a session the attacker already knows, then take over that authenticated session. The public disclosures deliberately withhold the precise delivery and code-level mechanism, so operators should not assume a particular login flow, proxy setting or deployment pattern makes them safe. The CVSS record indicates user interaction is involved, but the available material does not specify what that interaction looks like.

The observed chain reaches root

On its own, the flaw can lead to remote code execution as the zammad service user. In the documented DIVD intrusion, attackers chained it with CVE-2026-102490, a local privilege-escalation issue, and moved from session hijacking to execution as zammad and then root in seconds. Root access turns a compromised helpdesk host into an operating-system incident: attackers can alter services, read application secrets, access attached storage and pivot to reachable systems.

This is not a theoretical pairing. DIVD says malicious access to its environment began on September 21, 2026, and its vulnerability case record describes both issues as actively exploited. CVE-2026-102489 was added to CISA's Known Exploited Vulnerabilities catalogue on October 2, with an October 5 federal remediation deadline; the CISA endpoint was unavailable during the research, but current feed mirrors list the entry. No public proof of concept or exploit code had surfaced as of October 2. DIVD's published log-checking material is a defensive detection aid, not exploit code.

Version 6.x needs an exit plan, not a workaround

The version picture has one important wrinkle. DIVD and the Dutch NCSC treat 6.3.0 through 6.5.4 as exploitable. Zammad's own statement describes 6.5 and older as practically exploitable; it says the relevant pattern exists in 7.x but is not exploitable under those releases' runtime conditions. The vendor additionally hardened the code in 7.2.0 and recommends upgrading to that release.

There is no identified backport for the unsupported 6.x line. Teams on it should treat this as an urgent migration: take a supported backup, upgrade to 7.2.0, and do not mistake a compensating control for a fix. Operators already on 7.0 or 7.1 should also install 7.2.0 rather than relying on environmental conditions that may differ from the vendor's assumptions.

Helpdesk exposure deserves incident-response attention

Self-hosted Zammad is common across IT, retail, manufacturing, healthcare, education, legal services, NGOs, telecommunications, media and public administration. External support desks are obvious targets, but internal service desks can be even more valuable because their tickets reveal staff identities, infrastructure details and reset or onboarding workflows. Organisations using Zammad's vendor-operated cloud service should confirm their service's remediation status with the provider; the public material does not establish which hosted environments were exposed.

Review DIVD's indicators, preserve logs before rotation, hunt for anomalous Zammad sessions and processes running as zammad, and assume a server-level investigation is warranted where indicators appear. For the next flaw in this stack, SecAlerts monitors an organisation's actual software stack and alerts on new vulnerabilities affecting the products it runs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
Zammad Sessions Become Code Execution, Then Root - SecAlerts