Chaining Zammad Zero-Days — What You

Secably Research
Oct 05, 2026
4 min read
Vulnerability Research
Chaining Cve Vulnerability Zammad Zero-
Chaining Zammad Zero-Days — What You
Chaining Zammad Zero-Days — What You

Chaining Zammad Zero-Day Vulnerabilities for Root Access

The Dutch Institute for Vulnerability Disclosure (DIVD) recently experienced a breach of its internal ticketing system, Zammad. Attackers exploited two previously unknown zero-day vulnerabilities, CVE-2026-102489 and CVE-2026-102490, to gain full root access to their systems. This attack chain highlights the critical risk posed by such vulnerabilities, especially when combined. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added both flaws to its Known Exploited Vulnerabilities (KEV) catalog on October 2, 2026.

What the Vulnerability Is and Its Impact

The attack involved Chaining Zammad Zero-days to compromise the system. CVE-2026-102489 is a session hijacking vulnerability in Zammad. It enables remote code execution (RCE) as the `zammad` user. This flaw affects Zammad versions 6.3.0 through 6.5.4 directly. The same vulnerable code exists in versions 7.0.0 through 7.1.3, but environmental conditions prevent exploitation in those versions. CVE-2026-102490 is a local privilege escalation (LPE) vulnerability. It allows the local `zammad` user to gain root privileges. This vulnerability affects a broad range of Zammad versions, from 1.5.0 through 7.1.0-alpha. When chained, these two vulnerabilities carry a critical CVSS score of 9.4. Successful exploitation permits an unauthenticated remote attacker to achieve complete root-level takeover of the host operating system.

Technical Root Cause Analysis

CVE-2026-102489 stems from a session fixation weakness (CWE-384). This allows an attacker to hijack an existing Zammad user's session. Once a session is hijacked, the attacker can execute code with the privileges of the `zammad` service account. The `zammad` account often has extensive access to application files, databases, logs, and internal services. CVE-2026-102490 is an improper privilege management vulnerability. This flaw allows a local user, specifically the `zammad` user, to escalate privileges to `root`. This LPE effectively removes the privilege boundary that normally contains the Zammad application. This turns an application compromise into a full operating system compromise.

Exploitation Mechanics

The Chaining Zammad Zero-day vulnerabilities allowed for rapid system compromise. Attackers first exploit CVE-2026-102489 to gain initial remote code execution as the `zammad` user. This initial access is typically achieved through a hijacked session. No specific user interaction or prior privileges are required for this stage. Once code execution is established as the `zammad` user, the attacker then exploits CVE-2026-102490. This second vulnerability elevates their privileges to `root`. The entire process, from initial access to root, can take seconds. The use of an AI agent facilitated this speed, making decisions and executing steps without human latency. The technical details of the specific RCE payload for CVE-2026-102489 and the LPE mechanism for CVE-2026-102490 have not been publicly detailed by DIVD to prevent weaponization.

Detection: How to Check If You're Affected

Administrators must immediately check their Zammad instances. Verify your Zammad version against the affected ranges: 6.3.0 through 6.5.4 and 7.0.0 through 7.1.3 for CVE-2026-102489. For CVE-2026-102490, all versions from 1.5.0 through 7.1.0-alpha are potentially affected. DIVD has published a script to check Zammad application and web logs for signs of abuse. Run this script against your logs. Any match indicates a potential compromise and requires immediate incident response. Look for unusual process execution under the `zammad` user or any privilege escalation attempts. A service account should never change its effective user ID to `root`; this is a high-fidelity signal of compromise. You can use a free website vulnerability scanner to identify your Zammad version and other web-facing vulnerabilities. Additionally, the technology stack detector can help identify Zammad instances within your attack surface. For internet-wide scanning and exposed services, tools like Zondex can help identify publicly accessible Zammad instances.

Remediation Steps

The primary remediation is to upgrade Zammad to version 7.2.0 or later. Zammad version 7 is considered the safe release. Version 7.2.0 includes security hardening for CVE-2026-102489. Zammad has not released an official patch for CVE-2026-102490 as of October 2, 2026. Continue monitoring Zammad's security advisories for updates on CVE-2026-102490. If immediate upgrade is not feasible, take affected Zammad instances offline. Isolate the Zammad host from the rest of your network using strict network segmentation. Restrict its outbound access to only necessary services. Preserve all application, web server, authentication, and system logs before remediation. Rotate all potentially exposed credentials. Investigate any unauthorized session activity or command execution. Treat any confirmed exploitation as a root-level compromise of the host.

Timeline of Disclosure

The incident unfolded rapidly.
  • September 21, 2026: Attackers gained initial access to DIVD systems.
  • September 22, 2026: DIVD detected the intrusion and initiated a forensic investigation with Merlon Security.
  • September 22-23, 2026: DIVD analyzed and reproduced the vulnerabilities.
  • September 24, 2026: DIVD reported the findings to Zammad.
  • September 26, 2026: DIVD began scanning for internet-exposed Zammad instances and notifying affected owners.
  • September 30, 2026: DIVD publicly announced the breach and disclosed the two zero-day vulnerabilities. They published CVE-2026-102489 and CVE-2026-102490.
  • October 1, 2026: DIVD confirmed data exfiltration.
  • October 2, 2026: CISA added both CVE-2026-102489 and CVE-2026-102490 to its Known Exploited Vulnerabilities catalog.
  • October 5, 2026: CISA's Binding Operational Directive 22-01 mandates federal agencies to fix these flaws by this date.

Check your site for vulnerabilities

Run a free security scan — no signup, results in seconds.

Related Posts

Stronger security starts with visibility.

Scan your website for vulnerabilities and get actionable insights.