Zammad 0-Day Vulnerabilities Exploited to Gain Remote Code Execution and Root Access
Attackers exploited two Zammad zero-days for remote code execution and root, including a breach of DIVD.
Two Zammad zero-days, CVE-2026-102489 and CVE-2026-102490, were exploited in the wild, including against the Dutch Institute for Vulnerability Disclosure on 21 September 2026. CVE-2026-102489 is a session-hijacking flaw in Zammad 6.3.0 through 6.5.4 that can lead to remote command execution as the Zammad service user; the issue also exists in 7.0.0–7.1.3 but researchers said those releases were not exploitable under observed conditions. CVE-2026-102490 is a local privilege escalation to root affecting every version from 1.5.0 through 7.1.0-alpha. Chained, the bugs can yield full server control, ticket and attachment theft, and persistence; DIVD reported the issues on 24 September and recommends upgrading to version 7 or taking systems offline while noting the privilege-escalation bug still affects version 7.
- CVE-2026-102489 enables session hijacking and remote code execution as the Zammad user.
- It affects Zammad 6.3.0–6.5.4; versions 7.0.0–7.1.3 contain it but were not exploitable as tested.
- CVE-2026-102490 is a local root escalation affecting 1.5.0 through 7.1.0-alpha.
- An attacker used CVE-2026-102489 to compromise DIVD on 21 September 2026.
- DIVD urges upgrading to version 7 or taking instances offline and hunting for persistence.
Vulnerabilities mentionedAll →
- CVE-2026-1024899.4<1%Session hijack to RCE in Zammadpublished · Zammad KEV+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-102489+1 related CVE |
Full article478 words · extracted from cybersecuritynews.com · click to collapse
Two critical Zammad zero-day flaws, reportedly exploited against the Dutch Institute for Vulnerability Disclosure (DIVD), could allow session hijacking, remote command execution as the Zammad service user, and potential root privilege escalation.
The vulnerabilities are tracked as CVE-2026-102489 and CVE-2026-102490. DIVD published the findings under case DIVD-2026-00015 after investigating a separate breach case involving its own environment.
An attacker exploited CVE-2026-102489 to compromise DIVD on September 21, 2026, the session hijacking flaw affects Zammad 6.3.0–6.5.4 and can enable remote code execution as the Zammad user.
The issue also exists in Zammad versions 7.0.0 through 7.1.3, according to DIVD. However, researchers said it is not exploitable in those releases because of environmental conditions.
The second vulnerability, CVE-2026-102490, is a local privilege escalation flaw that affects all Zammad versions, including builds from version 1.5.0 through version 7.1.0-alpha.
An attacker who has already gained access as the local zammad user can exploit the vulnerability to elevate privileges to root, giving them full control over the affected server.
Zammad 0-Day Vulnerabilities Exploited
Together, the flaws form a high-impact attack chain. A remote attacker could exploit the session hijacking issue to run commands as the Zammad service account, then use the local privilege escalation flaw to obtain root-level access.
Root access could allow threat actors to alter helpdesk data, access customer support tickets, steal attachments, modify user accounts, install persistent backdoors, and move deeper into an organization’s network.
DIVD said its researchers analyzed and reproduced the vulnerabilities between September 22 and September 23. DIVD reported the findings to Zammad on September 24.
On September 26, DIVD began scanning for internet-exposed vulnerable Zammad instances and notifying affected owners. The organization also released a limited disclosure and said Zammad is working on a fix.

Security teams running Zammad should treat the flaws as an urgent incident-response issue. DIVD recommends upgrading to Zammad version 7 or taking affected instances offline until remediation is complete.
However, administrators should note that the local privilege escalation issue affects version 7 releases as well, including the latest alpha builds.
Organizations should review Zammad logs for evidence of suspicious sessions, unexpected administrative activity, unusual command execution, and changes involving the Zammad account. DIVD has provided an indicator-of-compromise log-check script to help administrators identify potential compromise.
Because the vulnerabilities were reportedly exploited before public disclosure, patching alone may not remove attacker persistence. Organizations that detect suspicious activity should isolate the server, rotate credentials and secrets, review account changes, inspect scheduled tasks and services, and conduct a full forensic investigation.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.