AI description
CVE-2026-102489 is a session hijacking and remote code execution vulnerability affecting Zammad, an open-source helpdesk and customer support ticketing system. The flaw allows unauthenticated attackers to leak user sessions and remotely execute malicious code as the local `zammad` user. It affects Zammad versions 6.3.0 through 6.5.4 in an exploitable state. While the vulnerability is present in versions 7.0.0 through 7.1.3, environmental conditions prevent its exploitation in those later releases. The vulnerability gained public attention after being exploited as a zero-day alongside CVE-2026-102490, a local privilege escalation flaw, in an automated, agentic AI-powered attack against the Dutch Institute for Vulnerability Disclosure (DIVD) in September 2026. By chaining these two vulnerabilities, the automated agent was able to hijack sessions, execute code, and escalate privileges to root within seconds. To mitigate the issue, users are advised to upgrade to Zammad version 7 or take vulnerable instances offline.
- Description
- Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
- Source
- csirt@divd.nl
- NVD status
- Analyzed
- Products
- zammad
CVSS 4.0
- Type
- Secondary
- Base score
- 9.4
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Zammad GmbH Zammad Session Fixation Vulnerability
- Exploit added on
- Oct 2, 2026
- Exploit action due
- Oct 5, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
7
🚨 CISA KEV — ZAMMAD CVE-2026-102489 + CVE-2026-102490 (SESSION FIXATION → RCE + LPE TO ROOT) CISA added two Zammad vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog on October 2, 2026, based on evidence of active exploitation. • Product: Zammad (help
@DailyDarkWeb
2 Oct 2026
3275 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🔴 Actively exploited: CISA confirms active exploitation of two critical Zammad flaws that lead to root access CVE-2026-102489 · CVE-2026-102490 CVE-2026-102489 and CVE-2026-102490, both rated CVSS 9.4, were added to CISA's KEV… #CVE #Zammad #infosec https://t.co/G8Ppqz4oI
@Orbitaley
2 Oct 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
csirt_it: ‼️ #Exploited #Zammad: rilevato sfruttamento attivo in rete delle vulnerabilità CVE-2026-102489 e CVE-2026-102490 Rischio: 🔴 Tipologia: 🔸 Remote Code Execution 🔸 Privilege Escalation 🔗 https://t.co/LVuz6tZqkT ⚠️ Importante mantenere agg… https
@Vulcanux_
2 Oct 2026
25 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
‼️ #Exploited #Zammad: rilevato sfruttamento attivo in rete delle vulnerabilità CVE-2026-102489 e CVE-2026-102490 Rischio: 🔴 Tipologia: 🔸 Remote Code Execution 🔸 Privilege Escalation 🔗 https://t.co/1tnc0Toes6 ⚠️ Importante mantenere aggiornati i sistemi h
@csirt_it
2 Oct 2026
282 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
News: DIVD was breached by an AI-led attack chaining Zammad zero-days CVE-2026-102489 and CVE-2026-102490. Sessions hijacked, root gained, data stolen. Upgrade to Zammad 7 or take it offline; check IoCs. https://t.co/qwThwq9asX
@snakeyesV1
2 Oct 2026
98 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers exploited Zammad zero-day flaws CVE-2026-102489 and CVE-2026-102490 to gain root at DIVD. Upgrade to Zammad 7 or go offline. #Zammad #ZeroDay #CVE2026102489 #CVE2026102490 #DIVD #AIAgent #ExploitedInTheWild https://t.co/A9KXk55U07
@Daily_CyberSec
2 Oct 2026
218 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
DIVD: AI 에이전트가 Zammad 제로데이로 침해(9/21). CVE-2026-102489 세션 하이재킹→RCE, CVE-2026-102490 로컬→root. 연쇄로 수 초 만에 권한 상승. 자원봉사자 이메일 등 유출 조사 중. Zammad 7 업그레이드 또는 오프라인 권고.
@none_gram
2 Oct 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
DIVD got hacked through AI agents that chained two Zammad zero-days: session hijack→RCE (CVE-2026-102489) and local root (CVE-2026-102490). Casefile published Sept 30. If you run Zammad, upgrade to 7 — or take it offline. https://t.co/Pxl88sJsXc
@justelite
1 Oct 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E9D8A954-62EA-4646-AB84-2A5080544473",
"versionEndExcluding": "6.5.4",
"versionStartIncluding": "6.3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F0888647-88A1-4B74-B55D-AB0AFDCEAF22",
"versionEndIncluding": "7.1.3",
"versionStartIncluding": "7.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:docker:docker:-:*:*:*:*:*:*:*",
"matchCriteriaId": "231A8A55-A319-4878-91DA-4FD91CF0549E",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*",
"matchCriteriaId": "703AF700-7A70-47E2-BC3A-7FD03B3CA9C1",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
]