If the help desk still runs Zammad 6.5 or older, the federal due date is today. CISA added two chained Zammad bugs to the Known Exploited Vulnerabilities catalog on October 2 and set both due dates at October 5. One is a remote session hijack. The other is a local jump to root. Together they are how a ticket system becomes the server.
The help desk on 6.5 has a due date of today.
What happened
CVE-2026-102489 is a session-fixation / session-hijack flaw. Zammad’s own write-up says versions 6.3.0 through 6.5.4 can be hijacked into remote code execution as the zammad user. The same code exists in 7.0.0 through 7.1.3, but Zammad and DIVD both say it is not practically exploitable there because of the runtime. Those 6.x lines are end of support. Zammad hardened the code in 7.2.0, the current stable release, and says it only ships security fixes for the current stable.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
CVE-2026-102490 is the second KEV entry: improper privilege management that can let the local zammad user become root, and CISA says it can be chained with the session bug. Zammad’s forum post is more careful than the catalog. The vendor first said DIVD had not shared technical details. A later update says the details arrived and Zammad is working on them, that the bug cannot be exploited remotely on its own, and that an attacker would already need access to the server. Do not treat 7.2.0 as a confirmed complete fix for the privilege bug until Zammad’s advisory says so. Do treat internet-facing 6.5 as in scope for the session bug today.
Why it matters
A help desk stores customer mail, internal notes, and often API tokens for the rest of the stack. Remote code execution as the application user is enough to read that. Chained to root, it is the host. Federal agencies are on the clock today; everyone else is on the same exploit, just without the directive.
The vendor and the catalog disagree on how finished the second bug is. The safe reading is: get off unsupported 6.x now, move to 7.2.0, keep the host off the internet, and watch Zammad’s security advisories for the privilege-bug patch.
What to do first
- Inventory Zammad version on every self-hosted instance, including the one a support lead installed and nobody owns.
- Anything on 6.5 or older: upgrade to 7.2.0 today. Those versions are out of security support, and that is the line where the session hijack is actually exploitable.
- Already on 7.0 or 7.1: move to 7.2.0 for the session hardening. Do not assume the local privilege issue is closed.
- Until the privilege advisory lands, do not expose the Zammad host to the internet. Restrict admin and the application port to the VPN.
- If the instance was internet-facing on 6.5, do the BOD-style triage: unexpected processes as the zammad user, new admin agents, odd Rails console history, and outbound connections you do not recognize.
- Zammad.com-hosted customers should confirm with the vendor that the hosted runtime is on 7.2.0. This brief’s action is for instances you run.
Forward this
If you own the help desk: Zammad 6.5 and older is past the point where “we’ll upgrade this month” is a plan. Move to 7.2.0 today and keep the server off the public internet until Zammad closes the local privilege bug.
Details
- CVE-2026-102489: session hijack to code execution as the zammad user. Practically exploitable on 6.3.0–6.5.4. Present but not practically exploitable on 7.0.0–7.1.3. Hardened in 7.2.0. CISA KEV added 2026-10-02, due 2026-10-05. CWE-384.
- CVE-2026-102490: local privilege management bug, zammad user toward root, chainable with the session bug per CISA. KEV added 2026-10-02, due 2026-10-05. Vendor says it is not remotely exploitable alone and that a fix is in progress after details arrived from DIVD.
- Action that is solid today: 7.2.0 for the session issue; network isolation and triage for the privilege issue.
Hunt / verify
- Confirm the running Zammad version, not the package you meant to install.
- On hosts that were exposed: review zammad user processes, new agent accounts, and unexpected cron or systemd units.
- Subscribe to https://github.com/zammad/zammad/security/advisories for the 102490 follow-up.
Slack paste: Zammad 6.5 and older: upgrade to 7.2.0 today (session hijack to code execution, KEV due Oct 5). Keep the host off the internet — the local root bug is still being patched. CVE-2026-102489 / CVE-2026-102490.
Sources
- https://www.cisa.gov/news-events/alerts/2026/10/02/cisa-adds-two-known-exploited-vulnerabilities-catalog
- https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297
- https://www.cve.org/CVERecord?id=CVE-2026-102489
- https://zammad.com/en/product/releases/
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.