SECURITYCRITICALCVE-2026-102489

CVE-2026-102489: Zammad Session Fixation Flaw Added to CISA KEV Catalog

CISA added CVE-2026-102489, a Zammad session fixation bug chaining to RCE as the zammad user, to its KEV catalog after active exploitation.

Dylan H.

Security Team

October 2, 2026
6 min read
CVE-2026-102489: Zammad Session Fixation Flaw Added to CISA KEV Catalog

Actively exploited

Reported as exploited in the wild (e.g. CISA KEV). Patch or mitigate immediately.

Affected Products

  • Zammad (open-source helpdesk/ticketing platform) versions 6.3.0 through 6.5.4 — exploitable
  • Zammad 7.0.0 through 7.1.3 — contain the underlying defect but are not practically exploitable due to environmental conditions; fully resolved in 7.2.0

Overview

On October 2, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-102489 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active in-the-wild exploitation of a critical session fixation vulnerability in Zammad, the open-source helpdesk and ticketing platform used by more than 2,000 organizations and 55,000+ users. The flaw lets an attacker fixate a victim's session and ride it to remote code execution as the zammad service account — and, per the KEV entry, is explicitly callable in a chain with its sibling flaw, CVE-2026-102490, a local privilege-escalation bug that completes the path from zammad to root on the underlying host.

This is not a theoretical pairing. The chain was used in a real breach: the Dutch Institute for Vulnerability Disclosure (DIVD) disclosed on October 1, 2026 that its own self-hosted Zammad instance was compromised on September 21, 2026 using exactly this CVE-2026-102489 → CVE-2026-102490 chain, reportedly by an autonomous AI agent that reached root within seconds of initial access (see CosmicBytez Labs' prior coverage of the DIVD breach for the incident narrative). The KEV listing formalizes what that incident already demonstrated: this is a live, exploited vulnerability, not a theoretical one.


Technical Details

FieldValue
CVE IDCVE-2026-102489
SeverityCritical — CVSS 9.4
CWECWE-384 — Session Fixation
Attack VectorNetwork — no authenticated account required; exploitation involves fixating and then hijacking a session against the Zammad instance
Affected VersionsZammad 6.3.0 through 6.5.4 (exploitable); the same code defect is present in 7.0.0 through 7.1.3 but environmental conditions in those releases prevent practical exploitation
Fixed VersionZammad 7.2.0
Chained WithCVE-2026-102490 — local privilege escalation from the low-privileged zammad service account to root; affects all known Zammad releases including current 7.x builds, and remains unpatched as of this advisory
KEV StatusAdded to the CISA KEV catalog October 2, 2026; federal agencies are required to remediate on an accelerated timeline under Binding Operational Directive 22-01

Exploitation status: Confirmed actively exploited. The DIVD breach is the first publicly documented use of this chain, and CISA's KEV addition reflects evidence of exploitation beyond that single incident.


How It Works

Zammad's session-handling logic fails to assign a fresh, unpredictable session identifier at a sensitive point in the authentication flow, allowing an attacker to fixate a session identifier before a victim authenticates. Once the victim's session is bound to a value the attacker already controls or can predict, the attacker can hijack that live session — effectively authenticating as the victim without needing their credentials. From that hijacked session, the vulnerability chain allows the attacker to achieve remote code execution running as the zammad service account on the host.

On its own, this flaw is already serious: it requires no prior authentication and is reachable over the network against any exposed Zammad instance. What makes it critical is what comes next. CVE-2026-102490 — a separate, currently unpatched local privilege-escalation flaw — lets anything running as the zammad service account escalate straight to root. Chained together, the two bugs form a complete, unauthenticated-to-root compromise path with no further barriers in between, which is exactly the sequence DIVD's incident report described: session hijacking, then RCE, then privilege escalation to root, all completed in seconds.


Impact Assessment

Who Is At Risk

Any organization running a self-hosted, internet-reachable Zammad instance on an affected 6.3.0–6.5.4 build — or on an unpatched 7.x build, given CVE-2026-102490 remains open across the entire 7.x line regardless of this fix. Zammad's broad install base (2,000+ organizations, 55,000+ users) means the exposure surface for this KEV entry is significant, particularly for instances that are internet-facing rather than restricted to internal networks.

Potential Attack Chains

  1. An unauthenticated attacker fixates a session against an exposed Zammad instance and hijacks it once a victim authenticates, gaining a foothold with no credentials of their own (CVE-2026-102489).
  2. That foothold yields code execution as the zammad service account.
  3. The attacker escalates from zammad to root using the unpatched CVE-2026-102490, gaining full control of the host — as demonstrated in the DIVD breach, enabling lateral movement and data exfiltration from connected systems.

Mitigation

Immediate Actions

  • Upgrade to Zammad 7.2.0, the first release confirmed to resolve CVE-2026-102489 in a practically exploitable configuration. Note this does not by itself close CVE-2026-102490 — treat that escalation path as still open.
  • Because CVE-2026-102490 has no available patch, isolate Zammad hosts on a restricted network segment, limit outbound connectivity from them, and avoid exposing Zammad directly to the public internet where feasible.
  • Rotate session secrets, API keys, and any credentials stored in or reachable from the Zammad instance, since a fixated session on a compromised instance should be treated as a prior-compromise indicator, not just a theoretical risk.
  • Federal agencies and any organization following BOD 22-01-style KEV guidance should prioritize this entry given its confirmed active exploitation and short remediation window.

Detection Opportunities

  • Review Zammad authentication and session logs for session identifiers that were active prior to a user's login — a hallmark of fixation — and for anomalous session reuse across different source IPs.
  • Monitor processes running under the zammad service account for unexpected child processes, privilege-escalation attempts, or activity inconsistent with normal helpdesk operations.
  • DIVD published a verification script following its own breach; Zammad operators should run it against application and web server logs to check for indicators of past exploitation of this same chain.

Defence-in-Depth

  • Apply least-privilege network segmentation to any system running Zammad or similar ticketing/helpdesk platforms — DIVD credited segmentation with preventing a deeper breach even after root was obtained on the Zammad host itself.
  • Treat helpdesk and ticketing platforms as sensitive infrastructure, not low-value utility services; they often hold contact data, credentials, and internal communications that make them attractive pivot points.
  • Track Zammad GmbH's advisories for the still-pending fix to CVE-2026-102490, and plan to patch promptly once it ships.

Background

CVE-2026-102489 and CVE-2026-102490 were first identified by DIVD working with Merlon Security following DIVD's own September 21, 2026 breach, in which an attacker — assessed by DIVD to be an autonomous AI agent — chained the two flaws to go from an unauthenticated foothold to root in seconds, then exfiltrated volunteer researcher contact data before network segmentation contained the intrusion. CosmicBytez Labs covered that incident in detail in Zammad Zero-Days Exploited in AI-Powered DIVD Hack.

CISA's October 2, 2026 KEV addition for CVE-2026-102489 formalizes that this is a confirmed, actively exploited vulnerability rather than a disclosed-but-theoretical one. Organizations running Zammad should treat CVE-2026-102489 and CVE-2026-102490 as a single compromise chain to remediate together: upgrading to 7.2.0 closes the entry point, but the escalation path to root remains open until Zammad GmbH ships a fix for CVE-2026-102490.


References