Zammad Vulnerabilities Enable Remote Code Execution and Root Privilege Escalation

Two newly disclosed vulnerabilities in the Zammad open-source helpdesk platform could let attackers achieve remote code execution and then escalate to root on affected servers.

DIVD CSIRT identified the flaws, tracked as CVE-2026-102489 and CVE-2026-102490, during its investigation into a separate security incident involving the organization.

DIVD said the vulnerabilities were actively abused on September 21, 2026, to breach its own environment. Its researchers subsequently analyzed and reproduced the attack chain before reporting the findings to Zammad on September 24.

Zammad Vulnerabilities

CVE-2026-102489 affects Zammad versions 6.3.0 through 6.5.4 and involves a session-hijacking issue that can result in remote code execution under the zammad user account.

An attacker who exploits the flaw could take control of the application-level Zammad account and execute commands on the underlying host, creating a foothold for further compromise.

The same underlying issue is also present in Zammad versions 7.0.0 through 7.1.3. However, DIVD stated that it is not currently exploitable in those releases because of environmental conditions.

Despite that limitation, organizations operating exposed Zammad systems should treat the finding as high risk, particularly where the platform contains customer support data, credentials, attachments, internal communications, and operational workflows.

The second vulnerability, CVE-2026-102490, affects a substantially wider version range. The local privilege-escalation flaw impacts Zammad versions beginning with 1.5.0 and continuing through version 7.1.0-alpha, including the latest alpha release at the time of disclosure.

A local attacker or an adversary who has already gained access as the zammad user could exploit the weakness to elevate privileges to root.

Together, the two vulnerabilities create a potentially severe attack path against Zammad deployments. A threat actor could use CVE-2026-102489 to hijack an application session and execute code as the Zammad service account, then use CVE-2026-102490 to obtain full root-level control of the host.

Root access would enable attackers to modify system files, deploy persistence mechanisms, access databases, steal credentials, tamper with logs, and potentially move laterally across connected infrastructure.

DIVD has advised all Zammad users to upgrade to version 7 or take affected instances offline until a secure remediation path is available. The organization also released a log-checking script designed to help administrators identify indicators of compromise associated with CVE-2026-102489.

Administrators should review Zammad logs, investigate unexpected session activity, inspect application and host-level command execution, rotate credentials, and assess whether the zammad account shows signs of unauthorized use.

DIVD began scanning for publicly exposed vulnerable Zammad instances on September 26 and started notifying identified owners the same day.

Organizations running internet-facing Zammad installations should prioritize incident-response checks, restrict external access where possible, and monitor vendor updates closely for fixes.

Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team 

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories