---
schema: 1
kind: vulnerability
title: "CVE-2026-102489 / CVE-2026-102490, Zammad helpdesk: a session-hijack remote code execution and a zammad-to-root escalation, both exploited since 21 September, and the root flaw is unfixed"
headline: "Two Zammad zero-days breached the Dutch DIVD; the national CERT says both are exploited, the root-escalation one unfixed"
summary: >
  DIVD, the Dutch vulnerability-disclosure CSIRT, says attackers entered its network on 2026-09-21 through two
  previously unknown Zammad flaws: CVE-2026-102489, a session hijack leading to code execution as the zammad user in
  versions 6.3.0 to 6.5.4, and CVE-2026-102490, a local escalation from that user to root in all versions. NCSC-NL
  states both have been exploited since 21 September, that an update exists only for the first, and that the second
  is not yet fixed.
discovered_at: "2026-10-02T04:45:00Z"
updated_at: null
event_date: "2026-09-30"
run_id: 2026-10-02T0404Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, rce, priv-esc, pre-auth, zero-day, actively-exploited, patch-available, no-patch, ai-abuse]
regions: [europe, dach]
sectors: [public-sector, technology]
entities: ["product:zammad"]
techniques: [T1190, T1068]
affected_products: ["Zammad"]
cves:
  - id: CVE-2026-102489
    cvss: "8.7 (CVSS 4.0 alone; 9.4 chained with CVE-2026-102490)"
    epss: 0.00709
    type: rce
    vector: user-interaction
    auth: pre-auth
    status: [exploited, patch-available]
    affected: "Zammad 6.3.0 through 6.5.4 (DIVD's case page and NCSC-NL); the DIVD CVE record states >= 6.3.0 to < 6.5.4; 7.0.0 through 7.1.3 contain the defect but DIVD says it is not exploitable there because of environment conditions"
    fixed: "Zammad has released a security update (NCSC-NL); no fixed build number appears in the DIVD or NCSC-NL pages, DIVD recommends upgrading to Zammad 7"
  - id: CVE-2026-102490
    cvss: "8.5 (CVSS 4.0 alone; 9.4 chained with CVE-2026-102489)"
    epss: 0.00319
    type: priv-esc
    vector: local
    auth: post-auth
    status: [exploited, no-patch]
    affected: "all Zammad versions from 1.5.0 including the latest alpha (DIVD's case page and NCSC-NL)"
    fixed: "No fix as of 2026-09-30 (NCSC-NL: not yet resolved); DIVD's case page lists patch status Available and recommends upgrading to Zammad 7 or taking the instance offline"
sources:
  - url: "https://www.ncsc.nl/alerts/actief-misbruik-van-zeroday-kwetsbaarheden-in-zammad-update-nu"
    publisher: "NCSC-NL"
    date: "2026-09-30"
    role: primary
  - url: "https://csirt.divd.nl/DIVD-2026-00015"
    publisher: "DIVD CSIRT (case DIVD-2026-00015)"
    date: "2026-10-01"
    role: primary
  - url: "https://csirt.divd.nl/cases/DIVD-2026-00014/"
    publisher: "DIVD CSIRT (case DIVD-2026-00014)"
    date: "2026-10-01"
    role: corroborating
  - url: "https://csirt.divd.nl/cves/CVE-2026-102489"
    publisher: "DIVD CSIRT (CVE record)"
    date: "2026-09-29"
    role: corroborating
  - url: "https://csirt.divd.nl/cves/CVE-2026-102490"
    publisher: "DIVD CSIRT (CVE record)"
    date: "2026-09-29"
    role: corroborating
closed_sources: []
evidence:
  - quote: "Both vulnerabilities have been actively exploited since 21 September 2026. (translated from Dutch)"
    original: "Beide kwetsbaarheden worden sinds 21 september 2026 actief misbruikt."
    publisher: "NCSC-NL"
    source_url: "https://www.ncsc.nl/alerts/actief-misbruik-van-zeroday-kwetsbaarheden-in-zammad-update-nu"
  - quote: "The second vulnerability (CVE-2026-102490) has not yet been resolved. (translated from Dutch)"
    original: "De tweede kwetsbaarheid (CVE-2026-102490) is nog niet opgelost."
    publisher: "NCSC-NL"
    source_url: "https://www.ncsc.nl/alerts/actief-misbruik-van-zeroday-kwetsbaarheden-in-zammad-update-nu"
  - quote: "We advise all users of Zammad to upgrade to version 7 of Zammad or to take it offline."
    publisher: "DIVD CSIRT"
    source_url: "https://csirt.divd.nl/DIVD-2026-00015"
  - quote: "In all versions of Zammad including the latest alpha has an vulnerability which enables the local zammad user to escalate privileges to root."
    publisher: "DIVD CSIRT"
    source_url: "https://csirt.divd.nl/DIVD-2026-00015"
verification: multi-source
sourcing_note: >
  The national CERT and the finder describe the same two flaws, but the finder is also the victim: DIVD's account of
  how it was breached is its own, and its assessment that the attack was driven by an AI agent rests on the attacker's
  scripts and is uncorroborated. Fixed builds are not named in any page read, no Zammad advisory was located on
  2026-10-02, and the sources differ on the root flaw: NCSC-NL says it is not fixed, DIVD's case page lists patch
  status Available, and DIVD's CVE record scopes it to versions below 7.1.0-alpha while its case page and NCSC-NL
  say all versions.
confidence: high
references:
  - 2026-06-18/bsi-flags-13-vulnerabilities-patched-in-zammad-7-1-admin-pri
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions:
  - "Find every self-hosted Zammad instance, copy its application and network logs before changing anything, upgrade to Zammad 7 (or take it offline if it cannot be upgraded), and run DIVD's log-check script against the logs for the code-execution flaw."
  - "Until a fix for CVE-2026-102490 is confirmed, keep Zammad off the internet or behind an authenticating reverse proxy or VPN and segment the ticket host from other internal services."
updates: []
migrated_from: null
---

DIVD, the Dutch Institute for Vulnerability Disclosure, says attackers first reached its systems on 2026-09-21 and that they got in through two zero-days in Zammad, the customer-service ticketing software, which together allowed session hijacking, remote code execution and privilege escalation from the Zammad user to root "in seconds" ([DIVD CSIRT, 2026-10-01](https://csirt.divd.nl/cases/DIVD-2026-00014/)). From there the attackers reached other services and exfiltrated data; DIVD says network segmentation and its incident response stopped them going deeper, and that volunteer data such as email addresses and possibly contact details left the network ([DIVD CSIRT, 2026-10-01](https://csirt.divd.nl/cases/DIVD-2026-00014/)). DIVD assesses the attack as driven by an AI agent, because the attacker's scripts carry notes in which the agent justifies its own actions, and says it sees no link to a known threat actor ([DIVD CSIRT, 2026-10-01](https://csirt.divd.nl/cases/DIVD-2026-00014/)).

CVE-2026-102489 is a session hijack that leads to remote code execution as the zammad user in versions 6.3.0 to 6.5.4; the defect is also present in 7.0.0 to 7.1.3 but DIVD says it is not exploitable there because of environment conditions ([DIVD CSIRT, 2026-10-01](https://csirt.divd.nl/DIVD-2026-00015)). NCSC-NL describes it as exploitable by an attacker who has not logged in ([NCSC-NL, 2026-09-30](https://www.ncsc.nl/alerts/actief-misbruik-van-zeroday-kwetsbaarheden-in-zammad-update-nu)), while DIVD's CVE record scores it CVSS 4.0 8.7 with passive user interaction ([DIVD CSIRT, 2026-09-29](https://csirt.divd.nl/cves/CVE-2026-102489)). CVE-2026-102490 lets the local zammad user escalate to root in all versions including the latest alpha, and DIVD scores the pair 9.4 when chained ([DIVD CSIRT, 2026-09-29](https://csirt.divd.nl/cves/CVE-2026-102490)). NCSC-NL states both flaws have been actively exploited since 2026-09-21, rates likelihood and damage as high, says Zammad has released an update for the first flaw only, and says the second "is not yet fixed" (translated from Dutch) ([NCSC-NL, 2026-09-30](https://www.ncsc.nl/alerts/actief-misbruik-van-zeroday-kwetsbaarheden-in-zammad-update-nu)). DIVD's case page instead lists patch status Available, recommends upgrading to Zammad 7 or taking Zammad offline, and says it is scanning for and notifying owners of vulnerable instances ([DIVD CSIRT, 2026-10-01](https://csirt.divd.nl/DIVD-2026-00015)).

**Exposure:** self-hosted Zammad. The code-execution flaw needs a version from 6.3.0 to 6.5.4; the root escalation is present in every version from 1.5.0, so it matters as the second stage after the code-execution flaw or any other foothold as the zammad user. No source says whether hosted Zammad is affected.

**Detection:** web and application logs on the Zammad host (DIVD publishes a log-check script for the code-execution flaw's indicators), process-creation events in which shells or interpreters are children of the Zammad service account, a privilege change from that account to root, and connections from the ticket host to internal services it does not normally contact ([DIVD CSIRT, 2026-10-01](https://csirt.divd.nl/DIVD-2026-00015)). Updating does not show whether an instance was already compromised: NCSC-NL asks operators to copy application and network logs before installing the update so the second flaw's use can be investigated later ([NCSC-NL, 2026-09-30](https://www.ncsc.nl/alerts/actief-misbruik-van-zeroday-kwetsbaarheden-in-zammad-update-nu)).

**Defender takeaway:** upgrade to Zammad 7 after saving the logs, and treat any internet-reachable instance on 6.3.0 to 6.5.4 since 2026-09-21 as possibly compromised, including the ticket data and anything the host can reach, since NCSC-NL says an attacker can take over the system, read, change or delete data and use it for further attacks; until the root flaw is confirmed fixed, keep Zammad behind authentication or off the internet and segmented, as DIVD credits segmentation for stopping its own intruders.
