Zammad Vulnerabilities Let Attackers Execute Code and Escalate Privileges to Root
Chained Zammad flaws CVE-2026-102489/102490 enable session hijacking, RCE, and root escalation; already used against DIVD.
DIVD and Merlon Security disclosed two Zammad vulnerabilities, CVE-2026-102489 (session hijacking leading to RCE as the Zammad service user, affecting 6.3.0–6.5.4) and CVE-2026-102490 (local privilege escalation to root, affecting 1.5.0 through 7.1.0-alpha). The chained attack carries a CVSS of 9.4 and was used in a September 21, 2026 intrusion against DIVD's own infrastructure that completed in seconds via an agentic AI-powered workflow. Fixes are included in Zammad 7.2.0; DIVD urges upgrading to version 7 and is scanning for and notifying exposed vulnerable instances.