Chained Zammad Helpdesk Flaws Gave Root Access in Breach of DIVD Ticketing System
Two zero-day vulnerabilities in the open-source Zammad helpdesk platform were added to the U.S. CISA Known Exploited Vulnerabilities catalog on 2 October 2026 after being used in a real intrusion. CVE-2026-102489, rated CVSS 9.4, is a session fixation weakness that allows session hijacking and ultimately remote code execution as the zammad service account; it affects Zammad 6.3.0 through 6.5.4 and 7.0.0 through 7.1.3. CVE-2026-102490, also rated CVSS 9.4, is an improper privilege management flaw that lets the local zammad user escalate to root, and it covers a far wider span of releases from 1.5.0 through 7.1.0-alpha. The flaws were uncovered by the Dutch Institute for Vulnerability Disclosure while it was investigating a breach of its own internal ticketing system, working alongside Merlon Security. With over 2,000 customers and roughly 55,000 users of the platform, any organisation running Zammad as a customer-facing or internal service desk should assume it is in scope until it has checked its version.
The two flaws were used together rather than in isolation, with the session fixation issue in CVE-2026-102489 providing the way in and the improper privilege management issue in CVE-2026-102490 turning that access into root on the underlying host. No technical write-up of the exploitation steps has been published while the investigation continues, so the mechanics of the chain beyond that sequence are not publicly established. What the affected organisation has described is that the operator drove the chain with an AI agent and that the run from initial access to root took seconds, after which other services on the compromised infrastructure were reached, data was accessed and some of it was exfiltrated. Network segmentation and a fast response from the victim's IT and incident response teams stopped further movement, although the organisation has stated that some damage had already occurred before containment, and further public updates have been promised.
The strategic concern is twofold. First, helpdesk platforms are a high-value target by design: they hold support tickets, attachments, customer contact data, internal notes and often credentials pasted by users, and they frequently sit in a network position that touches mail, identity and internal applications. A root shell on that host is effectively a foothold into the support side of the business, which is exactly the path the attackers took. Second, this case is a concrete data point that agent-driven exploitation has moved from theory into practice. The speed of the chain removed the usual human dwell time that defenders rely on to detect and interrupt an intrusion, and the victim noted that detection was helped only because the agent was comparatively noisy and left visible traces, meaning a more careful operator running the same tooling would be considerably harder to catch. On current exploitation status, both CVE-2026-102489 and CVE-2026-102490 are confirmed exploited in the wild and are listed in the CISA KEV catalog as of 2 October 2026, with FIRST EPSS placing the probability of exploitation over the next 30 days at 1.4% and 0.6% respectively; the low EPSS figures reflect modelled volume across the internet and do not soften the fact that real-world abuse has already been observed. Zammad has identified version 7 as the safe release and the affected organisation is notifying owners of exposed instances, while federal civilian agencies in the United States fall under Binding Operational Directive 22-01 with a remediation deadline of 5 October 2026.
Attack Surface
Web Application, Server OS
Tactics
Initial Access, Execution, Privilege Escalation, Credential Access, Lateral Movement, Exfiltration
Techniques
- T1190 – Exploit Public-Facing Application
- T1563 – Remote Service Session Hijacking
- T1539 – Steal Web Session Cookie
- T1068 – Exploitation for Privilege Escalation
- T1210 – Exploitation of Remote Services
- T1041 – Exfiltration Over C2 Channel
SuperPRO's Threat Countermeasures Procedures
- Inventory every Zammad instance and compare against the affected ranges: 6.3.0 through 6.5.4 and 7.0.0 through 7.1.3 for the session hijacking flaw CVE-2026-102489, and 1.5.0 through 7.1.0-alpha for the root privilege escalation flaw CVE-2026-102490. Update to Zammad version 7, which the vendor identifies as the safe release.
- Where the update cannot be completed in the same maintenance window, apply the published guidance that "If you run any version of Zammad, update to version 7 or take it offline as soon as possible", or at minimum remove the Zammad web interface from internet exposure and restrict it to VPN or trusted admin source addresses.
- Run the log-checking script published by DIVD against Zammad application and web logs to identify signs of abuse, and treat any match as an incident response case rather than a patching task, since exploitation preceded public disclosure.
- Check whether your organisation has received a notification from the Dutch Institute for Vulnerability Disclosure, which is contacting the owners of exposed Zammad instances, and treat any such notification as confirmation that an internet-reachable instance was identified in your address space.
- Where the DIVD log check indicates abuse of a Zammad instance, scope the investigation beyond the Zammad host itself to the other services running on the same infrastructure, since in the disclosed intrusion root access was used to reach adjacent services, access data and exfiltrate some of it. Treat the affected host as compromised at root level given CVE-2026-102490 grants root on the underlying system.
- Enforce and verify network segmentation around the Zammad host, restricting its outbound access to only the services it genuinely needs, and alert on new connections from the helpdesk server to internal file shares, databases or identity services. Segmentation is what limited the blast radius in the disclosed intrusion.
- U.S. federal civilian agencies must remediate both CVEs by the BOD 22-01 due date of 5 October 2026; other organisations should schedule the Zammad 7 upgrade against the same deadline given confirmed in-the-wild exploitation.