CVE-2026-102489

Published Sep 30, 2026

Last updated 4 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-102489 is a session hijacking and remote code execution vulnerability affecting Zammad, an open-source helpdesk and customer support ticketing system. The flaw allows unauthenticated attackers to leak user sessions and remotely execute malicious code as the local `zammad` user. It affects Zammad versions 6.3.0 through 6.5.4 in an exploitable state. While the vulnerability is present in versions 7.0.0 through 7.1.3, environmental conditions prevent its exploitation in those later releases. The vulnerability gained public attention after being exploited as a zero-day alongside CVE-2026-102490, a local privilege escalation flaw, in an automated, agentic AI-powered attack against the Dutch Institute for Vulnerability Disclosure (DIVD) in September 2026. By chaining these two vulnerabilities, the automated agent was able to hijack sessions, execute code, and escalate privileges to root within seconds. To mitigate the issue, users are advised to upgrade to Zammad version 7 or take vulnerable instances offline.

Description
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
Source
csirt@divd.nl
NVD status
Analyzed
Products
zammad

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.4
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Zammad GmbH Zammad Session Fixation Vulnerability
Exploit added on
Oct 2, 2026
Exploit action due
Oct 5, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

nvd@nist.gov
CWE-384
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-384

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

7

  1. 🚨 CISA KEV — ZAMMAD CVE-2026-102489 + CVE-2026-102490 (SESSION FIXATION → RCE + LPE TO ROOT) CISA added two Zammad vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog on October 2, 2026, based on evidence of active exploitation. • Product: Zammad (help

    @DailyDarkWeb

    2 Oct 2026

    3275 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🔴 Actively exploited: CISA confirms active exploitation of two critical Zammad flaws that lead to root access CVE-2026-102489 · CVE-2026-102490 CVE-2026-102489 and CVE-2026-102490, both rated CVSS 9.4, were added to CISA's KEV… #CVE #Zammad #infosec https://t.co/G8Ppqz4oI

    @Orbitaley

    2 Oct 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. csirt_it: ‼️ #Exploited #Zammad: rilevato sfruttamento attivo in rete delle vulnerabilità CVE-2026-102489 e CVE-2026-102490 Rischio: 🔴 Tipologia: 🔸 Remote Code Execution 🔸 Privilege Escalation 🔗 https://t.co/LVuz6tZqkT ⚠️ Importante mantenere agg… https

    @Vulcanux_

    2 Oct 2026

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. ‼️ #Exploited #Zammad: rilevato sfruttamento attivo in rete delle vulnerabilità CVE-2026-102489 e CVE-2026-102490 Rischio: 🔴 Tipologia: 🔸 Remote Code Execution 🔸 Privilege Escalation 🔗 https://t.co/1tnc0Toes6 ⚠️ Importante mantenere aggiornati i sistemi h

    @csirt_it

    2 Oct 2026

    282 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. News: DIVD was breached by an AI-led attack chaining Zammad zero-days CVE-2026-102489 and CVE-2026-102490. Sessions hijacked, root gained, data stolen. Upgrade to Zammad 7 or take it offline; check IoCs. https://t.co/qwThwq9asX

    @snakeyesV1

    2 Oct 2026

    98 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Attackers exploited Zammad zero-day flaws CVE-2026-102489 and CVE-2026-102490 to gain root at DIVD. Upgrade to Zammad 7 or go offline. #Zammad #ZeroDay #CVE2026102489 #CVE2026102490 #DIVD #AIAgent #ExploitedInTheWild https://t.co/A9KXk55U07

    @Daily_CyberSec

    2 Oct 2026

    218 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. DIVD: AI 에이전트가 Zammad 제로데이로 침해(9/21). CVE-2026-102489 세션 하이재킹→RCE, CVE-2026-102490 로컬→root. 연쇄로 수 초 만에 권한 상승. 자원봉사자 이메일 등 유출 조사 중. Zammad 7 업그레이드 또는 오프라인 권고.

    @none_gram

    2 Oct 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. DIVD got hacked through AI agents that chained two Zammad zero-days: session hijack→RCE (CVE-2026-102489) and local root (CVE-2026-102490). Casefile published Sept 30. If you run Zammad, upgrade to 7 — or take it offline. https://t.co/Pxl88sJsXc

    @justelite

    1 Oct 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations