If the help desk is still on Zammad 6.5, today is the due date

By George Bailey   Published: 10/05/26   Updated: 10/05/26   4 min read

If the help desk still runs Zammad 6.5 or older, the federal due date is today. CISA added two chained Zammad bugs to the Known Exploited Vulnerabilities catalog on October 2 and set both due dates at October 5. One is a remote session hijack. The other is a local jump to root. Together they are how a ticket system becomes the server.

The help desk on 6.5 has a due date of today.

What happened

CVE-2026-102489 is a session-fixation / session-hijack flaw. Zammad’s own write-up says versions 6.3.0 through 6.5.4 can be hijacked into remote code execution as the zammad user. The same code exists in 7.0.0 through 7.1.3, but Zammad and DIVD both say it is not practically exploitable there because of the runtime. Those 6.x lines are end of support. Zammad hardened the code in 7.2.0, the current stable release, and says it only ships security fixes for the current stable.

CVE-2026-102490 is the second KEV entry: improper privilege management that can let the local zammad user become root, and CISA says it can be chained with the session bug. Zammad’s forum post is more careful than the catalog. The vendor first said DIVD had not shared technical details. A later update says the details arrived and Zammad is working on them, that the bug cannot be exploited remotely on its own, and that an attacker would already need access to the server. Do not treat 7.2.0 as a confirmed complete fix for the privilege bug until Zammad’s advisory says so. Do treat internet-facing 6.5 as in scope for the session bug today.

Why it matters

A help desk stores customer mail, internal notes, and often API tokens for the rest of the stack. Remote code execution as the application user is enough to read that. Chained to root, it is the host. Federal agencies are on the clock today; everyone else is on the same exploit, just without the directive.

The vendor and the catalog disagree on how finished the second bug is. The safe reading is: get off unsupported 6.x now, move to 7.2.0, keep the host off the internet, and watch Zammad’s security advisories for the privilege-bug patch.

What to do first

Forward this

If you own the help desk: Zammad 6.5 and older is past the point where “we’ll upgrade this month” is a plan. Move to 7.2.0 today and keep the server off the public internet until Zammad closes the local privilege bug.

Details

Hunt / verify

Slack paste: Zammad 6.5 and older: upgrade to 7.2.0 today (session hijack to code execution, KEV due Oct 5). Keep the host off the internet — the local root bug is still being patched. CVE-2026-102489 / CVE-2026-102490.

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.