CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Zammad, privilege escalation (CVSS 4.0 8.5, 9.4 chained with CVE-2026-102489), exploited in the DIVD breach

cve · CVE-2026-102490

Coverage
1
first 2026-10-02 → last 2026-10-02
Latest activity
2026-10-02
Two Zammad zero-days breached the Dutch DIVD; the national CERT says both are exploited, the root-escalation…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, technology · regions: europe, dach
Sources cited
5
2 hosts

Action items (2)

Do-now tasks recorded on the entries about CVE-2026-102490, newest first. Check the date before acting on an older one.

  • Find every self-hosted Zammad instance, copy its application and network logs before changing anything, upgrade to Zammad 7 (or take it offline if it cannot be upgraded), and run DIVD's log-check script against the logs for the code-execution flaw.
    2026-10-02CVE-2026-102489 +1
  • Until a fix for CVE-2026-102490 is confirmed, keep Zammad off the internet or behind an authenticating reverse proxy or VPN and segment the ticket host from other internal services.
    2026-10-02CVE-2026-102489 +1

Defender insights

What each entry about CVE-2026-102490 tells a defender to do, newest first.

2026-10-02HIGHexploitedTwo Zammad zero-days breached the Dutch DIVD; the national CERT says both are exploited, the root-escalation one unfixed

Detection

Story timeline

  1. 2026-10-02CVE-2026-102489 / CVE-2026-102490, Zammad helpdesk: a session-hijack remote code execution and a zammad-to-root escalation, both exploited since 21 September, and the root flaw is unfixed
    trending-vulnerabilitiesTwo Zammad zero-days breached the Dutch DIVD; the national CERT says both are exploited, the root-escalation one unfixed
ATT&CK techniques (2 across 2 tactics)

2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application
  • Privilege EscalationExploitation for Privilege Escalation

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-10-02/zammad-cve-2026-102489-102490-exploited-divd-breach · ATT&CK page ↗

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×1

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-10-02/zammad-cve-2026-102489-102490-exploited-divd-breach · ATT&CK page ↗

Entries about Zammad, privilege escalation (CVSS 4.0 8.5, 9.4 chained with CVE-2026-102489), exploited in the DIVD breach (1)

2026-10-02 · view entry permalink →

HIGHCVE-2026-102489 +1exploitedNATOA2

CVE-2026-102489 / CVE-2026-102490, Zammad helpdesk: a session-hijack remote code execution and a zammad-to-root escalation, both exploited since 21 September, and the root flaw is unfixed

DIVD, the Dutch Institute for Vulnerability Disclosure, says attackers first reached its systems on 2026-09-21 and that they got in through two zero-days in Zammad, the customer-service ticketing software, which together allowed session hijacking, remote code execution and privilege escalation from the Zammad user to root "in seconds" (DIVD CSIRT, 2026-10-01). From there the attackers reached other services and exfiltrated data; DIVD says network segmentation and its incident response stopped them going deeper, and that volunteer data such as email addresses and possibly contact details left the network (DIVD CSIRT, 2026-10-01). DIVD assesses the attack as driven by an AI agent, because the attacker's scripts carry notes in which the agent justifies its own actions, and says it sees no link to a known threat actor (DIVD CSIRT, 2026-10-01).

CVE-2026-102489 is a session hijack that leads to remote code execution as the zammad user in versions 6.3.0 to 6.5.4; the defect is also present in 7.0.0 to 7.1.3 but DIVD says it is not exploitable there because of environment conditions (DIVD CSIRT, 2026-10-01). NCSC-NL describes it as exploitable by an attacker who has not logged in (NCSC-NL, 2026-09-30), while DIVD's CVE record scores it CVSS 4.0 8.7 with passive user interaction (DIVD CSIRT, 2026-09-29). CVE-2026-102490 lets the local zammad user escalate to root in all versions including the latest alpha, and DIVD scores the pair 9.4 when chained (DIVD CSIRT, 2026-09-29). NCSC-NL states both flaws have been actively exploited since 2026-09-21, rates likelihood and damage as high, says Zammad has released an update for the first flaw only, and says the second "is not yet fixed" (translated from Dutch) (NCSC-NL, 2026-09-30). DIVD's case page instead lists patch status Available, recommends upgrading to Zammad 7 or taking Zammad offline, and says it is scanning for and notifying owners of vulnerable instances (DIVD CSIRT, 2026-10-01).

Exposure: self-hosted Zammad. The code-execution flaw needs a version from 6.3.0 to 6.5.4; the root escalation is present in every version from 1.5.0, so it matters as the second stage after the code-execution flaw or any other foothold as the zammad user. No source says whether hosted Zammad is affected.

Both vulnerabilities have been actively exploited since 21 September 2026. (translated from Dutch)

The second vulnerability (CVE-2026-102490) has not yet been resolved. (translated from Dutch)

NCSC-NL 2026-09-30

We advise all users of Zammad to upgrade to version 7 of Zammad or to take it offline.

In all versions of Zammad including the latest alpha has an vulnerability which enables the local zammad user to escalate privileges to root.

DIVD CSIRT

Builds on: BSI flags 13 vulnerabilities patched in Zammad 7.1, admin privilege escalation in a DACH…

vulnerability02 Oct 04:45Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • csirt.divd.nl4 (80%)
  • ncsc.nl1 (20%)