Overview
CVE-2026-102490 is an improper privilege management vulnerability in Zammad, the open-source customer support/helpdesk platform from Zammad GmbH. The flaw allows the local, low-privileged zammad service account to escalate its privileges to root on the underlying host.
Unlike a typical remote exploit, this vulnerability requires an attacker to already have code execution or shell access as the zammad user before it can be triggered. That precondition is exactly what makes it dangerous in practice: it was discovered and weaponized alongside a second flaw, CVE-2026-102489 (a session-fixation vulnerability that enables remote session hijacking and code execution as zammad). Chained together, the two bugs let an attacker go from an unauthenticated remote foothold to full root compromise of a Zammad host.
This chain was not theoretical. According to the Dutch Institute for Vulnerability Disclosure (DIVD), working with Merlon Security, both CVEs were used in a real-world breach of DIVD's own infrastructure on September 21, 2026, reportedly carried out by an autonomous, agentic AI-driven threat actor that moved from session hijack to root access "in seconds." Both CVEs were added to the CISA Known Exploited Vulnerabilities (KEV) catalog on October 2, 2026 on the basis of this confirmed in-the-wild exploitation.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-102490 |
| Severity | Critical |
| CWE | CWE-269 — Improper Privilege Management |
| Attack Vector | Local |
| Privileges Required | Low (requires existing zammad user-level code execution) |
| User Interaction | None |
| CVSS | Reported in the ~8.5–9.8 range depending on source and scoring context; DIVD rates the chained scenario (with CVE-2026-102489) at 9.4 (Critical) |
| Impact | Local privilege escalation from the zammad service account to root |
| Chained With | CVE-2026-102489 (session fixation / remote code execution as zammad) |
| CISA KEV | Added October 2, 2026; federal remediation deadline October 5, 2026 |
| Patch Status | No vendor-confirmed fix as of this writing |
Public CVSS figures for this CVE are inconsistent across trackers — some rate it high (≈8.5) when scored as a standalone local issue, while others score it critical (9.4–9.8) once the realistic chained-exploitation path is factored in. We present the range here rather than a single authoritative figure because, as of publication, Zammad GmbH has stated it has not received sufficient technical detail from DIVD to confirm the flaw's scope or affected releases — meaning official vendor scoring and an enumerated affected-version list are not yet settled.
How It Works
Zammad runs its application processes under a dedicated, unprivileged zammad system account — standard practice for limiting blast radius if the web application is compromised. CVE-2026-102490's CWE-269 classification (Improper Privilege Management) indicates that somewhere in Zammad's local operation — such as a helper process, scheduled job, file permission, or privileged handoff that the zammad user can influence — insufficient restrictions allow that account to escalate to root. Neither Zammad nor DIVD has published a full technical root-cause writeup at the time of this advisory, so the precise mechanism (e.g., a writable root-owned script, an unsafe sudo rule, or a setuid helper) has not been independently confirmed.
What is confirmed is the practical exploitation path observed in the DIVD incident:
- An attacker (in DIVD's case, an autonomous AI agent) exploits CVE-2026-102489 remotely to hijack a valid Zammad session and achieve code execution as the
zammaduser. - From that foothold, the attacker leverages CVE-2026-102490 to escalate from
zammadto root — DIVD describes this step as happening "in seconds." - With root access, the attacker has unrestricted control of the host, including any co-located services, credentials, and data outside Zammad's own application boundary.
Impact Assessment
Who Is At Risk
Any organization self-hosting Zammad is potentially exposed, regardless of version — reporting indicates the underlying privilege-management flaw has been present from version 1.5.0 through the current 7.2.0 release, including the 7.1.0-alpha branch. Zammad GmbH reports over 2,000 customers and roughly 55,000 users, giving this a wide potential blast radius. Risk is highest for:
- Self-hosted Zammad instances where the application server also runs other sensitive services
- Deployments that have not yet applied the 7.2.0 hardening for CVE-2026-102489 (removing the easiest remote path into the
zammadaccount) - Environments without host-level monitoring that would catch an unprivileged service account suddenly spawning root processes
Potential Attack Chain
- Remote Foothold — Attacker hijacks a Zammad session via CVE-2026-102489, gaining code execution as
zammad - Privilege Escalation — Attacker exploits CVE-2026-102490 to escalate from
zammadto root - Full Host Compromise — With root, the attacker can read and exfiltrate ticket data and attachments, modify or create user accounts, install persistent backdoors, and pivot to other services on the same host or network
- Data Exposure — Helpdesk platforms like Zammad routinely contain sensitive customer communications, credentials shared in tickets, and internal operational detail — all exposed once root is obtained
Why This Matters Even After Patching CVE-2026-102489
Upgrading to Zammad 7.2.0 addresses the session-fixation issue (CVE-2026-102489) and removes the easiest remote path to a zammad-level foothold. However, multiple reports indicate that CVE-2026-102490 itself remains unpatched even on the latest release. An attacker who obtains zammad-level access through any other means (a different bug, leaked credentials, a misconfigured integration, etc.) could still escalate to root until Zammad GmbH ships a fix specifically for this flaw.
Mitigation
Immediate Actions
- Upgrade to Zammad 7.2.0 or later to close the CVE-2026-102489 remote entry point, reducing the realistic opportunities for an attacker to reach the
zammadaccount in the first place - Treat any Zammad host as at-risk of root compromise until Zammad GmbH publishes a dedicated fix for CVE-2026-102490 — there is currently no version that is confirmed to resolve it
- If a Zammad instance is internet-facing and cannot be promptly upgraded, consider taking it offline or restricting access to a trusted network/VPN, per DIVD's own guidance following its breach
- Monitor Zammad's official security advisories closely for a patch addressing CVE-2026-102490 specifically
Defence-in-Depth
- Run the Zammad application stack with the minimum OS privileges required, and avoid co-locating Zammad with other sensitive services on the same host
- Apply host hardening — restrict
sudo/setuid configurations, use read-only filesystems where feasible, and audit any scripts or cron jobs thezammadaccount can read or write - Deploy file integrity monitoring (FIM) and auditd-style process auditing to catch the
zammadaccount spawning unexpected root-owned processes - Segment Zammad hosts from critical infrastructure so that a host compromise does not automatically grant broader network access
- Rotate credentials and API tokens stored in or accessible from the Zammad environment as a precaution if exposure is suspected
Detection Opportunities
- Unexpected privilege transitions from the
zammadUID to root (e.g., viasudo,su, setuid binaries, or unusual child processes of Zammad worker processes) - Session anomalies consistent with fixation/hijacking (reused or unexpectedly long-lived session identifiers) ahead of any privilege escalation activity
- New or modified cron jobs, systemd units, or scripts owned by root but writable by the
zammadaccount - Outbound connections or data transfers initiated from previously dormant root processes shortly after
zammad-level activity
Background: The DIVD Breach
This advisory is notable beyond the usual CVE writeup because of its origin story: DIVD, a volunteer nonprofit dedicated to finding and disclosing vulnerabilities, was itself breached using these two Zammad flaws. DIVD has publicly stated that the intrusion was carried out with unusual speed and automation, consistent with an agentic AI system driving the attack chain end-to-end — hijacking a session, achieving code execution, and escalating to root with minimal human-attacker latency.
DIVD's own advice after the incident was blunt: update to Zammad 7 (or later) or take affected instances offline. Given that CVE-2026-102490 is not resolved by that upgrade alone, defenders should treat root-level compromise of any Zammad host as a standing risk until Zammad GmbH ships and confirms a dedicated fix.