DIVD-2026-00015 - Vulnerabilities in Zammad during investigation of case DIVD-2026-00014
Summary
During the investigation of case DIVD-2026-00014, two new CVEs were identified.
- CVE-2026-102489 - Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
- CVE-2026-102490 - In all versions of Zammad including the latest alpha has an vulnerability which enables the local zammad user to escalate privileges to root.
What you can do
We advise all users of Zammad to upgrade to version 7 of Zammad or to take it offline. If you want to investigate whether you have been compromised based on our IoCs, you can download our log check script to check your Zammad logfiles for Indicators of Compromise.
What we are doing
DIVD is actively scanning and alerting owners of vulnerable Zammad instances.
We have reported the vulnerability to Zammad who are working on a fix.
Timeline
gantt
title DIVD-2026-00015 - Vulnerabilities in Zammad during investigation of case DIVD-2026-00014
dateFormat YYYY-MM-DD
axisFormat %e %b %Y
section Case
DIVD-2026-00015 - Vulnerabilities in Zammad during investigation of case DIVD-2026-00014 (still open) :2026-09-24, 2026-10-09
section Events
Vulnerability abused to breach DIVD : milestone, 2026-09-21, 0d
Vulnerability analysed and reproduced by DIVD team (1 days) : 2026-09-22, 2026-09-23
Vulnerability reported to Zammad. : milestone, 2026-09-24, 0d
DIVD scanned for publicly available and vulnerable Zammad instances. : milestone, 2026-09-26, 0d
DIVD created a limited disclosure for CVE-2026-102489 & CVE-2026-102490. : milestone, 2026-09-26, 0d
DIVD started notifying owners of vulnerable instances. : milestone, 2026-09-26, 0d