Zammad CVE-2026-102489 on CISA KEV: patch your helpdesk
CISA added two exploited Zammad flaws to KEV. Chained, they turn a hijacked session into root on your helpdesk server. Upgrade to Zammad 7.2.0 and check for compromise.
Your helpdesk holds every customer email, every attachment, and often the password-reset conversations for your other systems. On October 2, CISA added two Zammad flaws to its Known Exploited Vulnerabilities catalog: Zammad CVE-2026-102489, a session fixation bug, and CVE-2026-102490, a privilege escalation bug. Chained, they take an attacker from a hijacked session to root on the server. If you self-host Zammad, upgrade to 7.2.0 and then check whether someone got there first.
What actually happened
The Dutch security nonprofit DIVD found both bugs while it investigated a real breach. Per the DIVD case file, the attack happened on September 21. DIVD reproduced it by September 23, notified Zammad on September 24, and began public scanning and victim notification on September 26.
The two pieces:
- CVE-2026-102489 lets an attacker hijack a session and run code as the
zammaduser. DIVD lists versions 6.3.0 through 6.5.4 as exploitable. It says 7.0.0 through 7.1.3 contain the flaw but environment conditions block exploitation. - CVE-2026-102490 lets the local
zammaduser escalate to root. DIVD says it reaches back to version 1.5.0.
Zammad's own community notice says the privilege bug cannot be exploited remotely by itself, because the attacker already needs access to the server. That is true, and it is also exactly what the first bug provides. Zammad tells customers to update to 7.2.0 now, and says installs on 6.5 or older are the priority.
Why it matters for your business
Old helpdesks are the soft target. A self-hosted ticket system often gets installed once and then left alone for years. The exploitable range here, 6.3 to 6.5, is exactly the "it works, don't touch it" install.
Patching does not undo a breach. CISA's notice tells agencies to check whether attackers compromised the system before the patch went on. Do the same. DIVD published an indicator-of-compromise check script with its case. Run it before you call this closed.
Root on the helpdesk is a pivot point. From that box, an attacker reads customer data, sends email that looks like your support team, and finds credentials for the systems the helpdesk talks to.
Key takeaways
- CISA added Zammad CVE-2026-102489 and CVE-2026-102490 to KEV on October 2
- Chained, the bugs turn a hijacked session into root on the server
- Versions 6.3.0 through 6.5.4 are the exploitable range for the session bug
- Upgrade to Zammad 7.2.0, then run DIVD's compromise check
- Rotate any credentials stored on or sent through the helpdesk if you find signs of access
Running a helpdesk nobody has touched in two years? We find the self-hosted tools that slipped out of your patch cycle, then upgrade them or move them to a setup with an owner and an update plan. See what we build, or ask us to check your stack.
Sources: CISA KEV alert, DIVD-2026-00015, Zammad community notice.
- #zammad
- #cve-2026-102489
- #cisa-kev
- #helpdesk
- #patch-management
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
IBM Bob goes self-hosted: an AI coding agent behind your firewall
IBM Bob, IBM's AI coding agent, now runs self-hosted, on-prem, and air-gapped with Nemotron or Poolside models. What it means for where your source code goes.
Read itTA419 faked an Anthropic exec to phish: MFA codes didn't help
Proofpoint says China-aligned TA419 impersonated an Anthropic employee and used browser-in-browser phishing to steal MFA codes and sessions. Move to passkeys.
Read it