DIVD-2026-00015 - Vulnerabilities in Zammad during investigation of case DIVD-2026-00014

Summary

During the investigation of case DIVD-2026-00014, two new CVEs were identified.

- CVE-2026-102489 - Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

- CVE-2026-102490 - In all versions of Zammad including the latest alpha has an vulnerability which enables the local zammad user to escalate privileges to root.

What you can do

We advise all users of Zammad to upgrade to version 7 of Zammad or to take it offline. If you want to investigate whether you have been compromised based on our IoCs, you can download our log check script to check your Zammad logfiles for Indicators of Compromise.

What we are doing

DIVD is actively scanning and alerting owners of vulnerable Zammad instances.

We have reported the vulnerability to Zammad who are working on a fix.

Timeline

gantt

title DIVD-2026-00015 - Vulnerabilities in Zammad during investigation of case DIVD-2026-00014

dateFormat YYYY-MM-DD

axisFormat %e %b %Y

section Case

DIVD-2026-00015 - Vulnerabilities in Zammad during investigation of case DIVD-2026-00014 (still open) :2026-09-24, 2026-10-09

section Events

Vulnerability abused to breach DIVD : milestone, 2026-09-21, 0d

Vulnerability analysed and reproduced by DIVD team (1 days) : 2026-09-22, 2026-09-23

Vulnerability reported to Zammad. : milestone, 2026-09-24, 0d

DIVD scanned for publicly available and vulnerable Zammad instances. : milestone, 2026-09-26, 0d

DIVD created a limited disclosure for CVE-2026-102489 & CVE-2026-102490. : milestone, 2026-09-26, 0d

DIVD started notifying owners of vulnerable instances. : milestone, 2026-09-26, 0d