CVE-2026-102489 is an unauthenticated session-fixation flaw in Zammad, the open-source web helpdesk used to handle customer support, internal IT tickets, HR requests and other casework. That makes the exposure broader than a typical support portal: a Zammad server often sits at the edge of an organisation, accepts email and web requests, and holds ticket histories, attachments, user data and integrations.
Session fixation means an attacker can arrange for a victim to use a session the attacker already knows, then take over that authenticated session. The public disclosures deliberately withhold the precise delivery and code-level mechanism, so operators should not assume a particular login flow, proxy setting or deployment pattern makes them safe. The CVSS record indicates user interaction is involved, but the available material does not specify what that interaction looks like.
The observed chain reaches root
On its own, the flaw can lead to remote code execution as the zammad service user. In the documented DIVD intrusion, attackers chained it with CVE-2026-102490, a local privilege-escalation issue, and moved from session hijacking to execution as zammad and then root in seconds. Root access turns a compromised helpdesk host into an operating-system incident: attackers can alter services, read application secrets, access attached storage and pivot to reachable systems.
This is not a theoretical pairing. DIVD says malicious access to its environment began on September 21, 2026, and its vulnerability case record describes both issues as actively exploited. CVE-2026-102489 was added to CISA's Known Exploited Vulnerabilities catalogue on October 2, with an October 5 federal remediation deadline; the CISA endpoint was unavailable during the research, but current feed mirrors list the entry. No public proof of concept or exploit code had surfaced as of October 2. DIVD's published log-checking material is a defensive detection aid, not exploit code.
Version 6.x needs an exit plan, not a workaround
The version picture has one important wrinkle. DIVD and the Dutch NCSC treat 6.3.0 through 6.5.4 as exploitable. Zammad's own statement describes 6.5 and older as practically exploitable; it says the relevant pattern exists in 7.x but is not exploitable under those releases' runtime conditions. The vendor additionally hardened the code in 7.2.0 and recommends upgrading to that release.
There is no identified backport for the unsupported 6.x line. Teams on it should treat this as an urgent migration: take a supported backup, upgrade to 7.2.0, and do not mistake a compensating control for a fix. Operators already on 7.0 or 7.1 should also install 7.2.0 rather than relying on environmental conditions that may differ from the vendor's assumptions.
Helpdesk exposure deserves incident-response attention
Self-hosted Zammad is common across IT, retail, manufacturing, healthcare, education, legal services, NGOs, telecommunications, media and public administration. External support desks are obvious targets, but internal service desks can be even more valuable because their tickets reveal staff identities, infrastructure details and reset or onboarding workflows. Organisations using Zammad's vendor-operated cloud service should confirm their service's remediation status with the provider; the public material does not establish which hosted environments were exposed.
Review DIVD's indicators, preserve logs before rotation, hunt for anomalous Zammad sessions and processes running as zammad, and assume a server-level investigation is warranted where indicators appear. For the next flaw in this stack, SecAlerts monitors an organisation's actual software stack and alerts on new vulnerabilities affecting the products it runs.




