Critical Zammad Flaws Let Attackers Gain Remote Code Execution
Key Takeaways Two critical zero-day vulnerabilities in the Zammad helpdesk software have been identified, with evidence of active exploitation. The flaws, CVE-2026-102489 and CVE-2026-102490, could...
Key Takeaways
- Two critical zero-day vulnerabilities in the Zammad helpdesk software have been identified, with evidence of active exploitation.
- The flaws, CVE-2026-102489 and CVE-2026-102490, could allow remote code execution and subsequent root privilege escalation.
- Multiple Zammad versions are affected, including 6.3.0–6.5.4 for remote code execution and all versions from 1.5.0 through 7.1.0-alpha for privilege escalation.
- A fix is currently being developed by Zammad; immediate mitigation steps include upgrading to Zammad 7 or taking vulnerable instances offline.
Critical Zammad Zero-Days Under Active Exploitation
Cybersecurity researchers have uncovered two critical zero-day vulnerabilities in the Zammad helpdesk system, which have reportedly been exploited in the wild. These flaws, tracked as CVE-2026-102489 and CVE-2026-102490, could enable attackers to achieve remote code execution (RCE) and elevate privileges to gain full control over affected servers.
Table Of Content
The Dutch Institute for Vulnerability Disclosure (DIVD) brought these findings to light under case DIVD-2026-00015, after their own environment was compromised. The institute’s investigation into an unrelated breach led to the discovery and analysis of these critical Zammad weaknesses.
Remote Code Execution via Session Hijacking
The first vulnerability, CVE-2026-102489, facilitates session hijacking and allows for remote code execution as the Zammad service user. DIVD confirmed that this flaw was exploited to breach their systems on September 21, 2026. This RCE vulnerability impacts Zammad versions 6.3.0 through 6.5.4.
While the issue is also present in Zammad versions 7.0.0 through 7.1.3, researchers noted that environmental factors prevent its exploitation in these newer releases.
Local Privilege Escalation to Root
The second vulnerability, CVE-2026-102490, is a local privilege escalation flaw. It affects a broad range of Zammad versions, from 1.5.0 up to and including the latest alpha builds of version 7.1.0-alpha. An attacker who has already secured access as the local zammad user can leverage this vulnerability to escalate their privileges to root, thereby gaining complete control over the compromised server.
Chaining Attacks for Maximum Impact
When combined, these two vulnerabilities create a devastating attack chain. A remote attacker could first exploit CVE-2026-102489 to execute arbitrary commands as the Zammad service account. Subsequently, they could utilize CVE-2026-102490 to escalate their access to root level. This level of access grants threat actors the ability to manipulate helpdesk data, access sensitive customer support tickets and attachments, modify user accounts, establish persistent backdoors, and expand their presence deeper into an organization’s network.
DIVD researchers meticulously analyzed and reproduced these vulnerabilities between September 22 and September 23, promptly reporting their findings to Zammad on September 24. By September 26, DIVD had initiated scans for vulnerable Zammad instances exposed to the internet, notifying affected organizations and issuing a limited disclosure while Zammad worked on developing a patch.
What You Should Do
- Upgrade Immediately or Isolate: Given the active exploitation, organizations running Zammad should treat this as an urgent incident. DIVD advises upgrading to Zammad version 7 or taking affected instances offline until a patch becomes available. Be aware that the local privilege escalation flaw (CVE-2026-102490) still affects version 7 releases, including alpha builds.
- Monitor Logs for Compromise: Review Zammad logs for any indicators of compromise (IoCs), such as suspicious sessions, unexpected administrative actions, unusual command executions, or modifications related to the Zammad account. DIVD has provided an IoC log-check script to assist administrators in identifying potential breaches.
- Post-Exploitation Remediation: Since these vulnerabilities have been actively exploited, patching alone may not remove attacker persistence. If suspicious activity is detected, immediately isolate the compromised server, rotate all associated credentials and secrets, review account changes, inspect scheduled tasks and services, and conduct a thorough forensic investigation to ensure complete remediation.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.