Zammad session fixation to root hits CISA KEV

Zammad session fixation to root hits CISA KEV

How to fix CVE-2026-102489: upgrade Zammad to 7.2.0 (leave 6.5 EOL trains; chain with CVE-2026-102490)

4 min read819 words
Contents

CISA added CVE-2026-102489 and CVE-2026-102490 to the Known Exploited Vulnerabilities catalog today (2026-10-02). The pair is a chain in the open-source Zammad helpdesk: session fixation that can reach remote code execution as the zammad user, then local privilege escalation from that user to root. CISA notes the two can be chained. KEV due date is 2026-10-05. Required action follows BOD 26-04 (risk-based patching plus forensic triage where applicable). Catalog version is 2026.10.02.

DIVD published the CVEs under case DIVD-2026-00015 after investigating its own network breach (case DIVD-2026-00014). DIVD says the chain was used in an automated attack against its Zammad instance. This page is the operator write-up from CISA KEV, the DIVD CVE records, and Zammad's community guidance. The HOL Guard evidence pack for CVE-2026-102489 is the linked source record (sibling CVE-2026-102490).

What breaks

CVE-2026-102489 (session fixation to RCE as zammad): DIVD rates CVSS 4.0 base 8.7 High (critical sibling vector 9.4). Attack vector is network, privileges none, user interaction passive, exploit maturity Attacked. DIVD marks Zammad 6.3.0 through versions before 6.5.4 as affected on Linux/Docker. Versions 7.0.0 and later are listed unaffected for practical exploitation; DIVD and Zammad both say the defect is present on some 7.x trains but not exploitable under those runtime conditions. Zammad states it hardened the code in 7.2.0.

CVE-2026-102490 (local privilege escalation to root): DIVD rates CVSS 4.0 base 8.5 High (critical sibling vector 9.4). Attack vector is local: an attacker who already runs as the zammad OS user can escalate to root. DIVD lists affected from 1.5.0 before 7.1.0-alpha. Zammad's community thread (2026-10-01) says it received technical details from DIVD and is working the fix, and that this issue cannot be exploited remotely on its own. CISA's KEV row explicitly says it can be chained with CVE-2026-102489.

Together: network path into RCE as zammad, then root on the host. That is why CISA put both on KEV the same day with a three-day due date.

Who is not in scope

  • Zammad 7.0+ for CVE-2026-102489 exploitation per DIVD product status and Zammad's 2026-10-01 statement: the session-to-RCE path is not practically exploitable on current 7.x runtime. Still upgrade to 7.2.0 for the hardening and for the LPE track.
  • Hosts where the attacker cannot reach the Zammad HTTP(S) UI and also cannot obtain a local zammad shell. The LPE alone is not a remote worm.
  • Non-Zammad helpdesks (Zendesk, Freshdesk, osTicket, and so on). These CVE IDs are Zammad GmbH Zammad only.
  • Cloud SaaS tenants on Zammad's hosted product only if your vendor confirms your tenant train is already on a fixed build. Self-hosted and Docker operators own the upgrade.

One operator check

On each self-hosted box, confirm the installed package version and whether the service is internet-facing:

# Debian/Ubuntu package installs
dpkg -l zammad | awk 'NR==1 || /^ii/'

# RPM installs
rpm -q zammad

# Docker / compose: inspect the image tag you actually run
docker ps --format '{{.Image}}' | grep -i zammad

# Confirm the UI listener is not on the public internet unless required
ss -lntp | egrep ':80|:443' 

If dpkg/rpm/docker shows anything older than 7.2.0, schedule the upgrade now. Federal and BOD 26-04 environments also owe forensic triage before they declare the host clean; KEV due date is 2026-10-05.

How to fix

Zammad's public guidance (community thread, 2026-10-01 / 2026-10-01 evening update): update to Zammad 7.2.0, the current stable release. If you still run Zammad 6.5 or older, update now; those trains no longer receive security fixes under Zammad's policy.

# Package-based self-host (follow your distro docs for the Zammad repo)
sudo apt-get update && sudo apt-get install --only-upgrade zammad
# or
sudo yum update zammad

# Then confirm
dpkg -l zammad
# expect 7.2.0 or newer on the Version column

Docker operators: pull and redeploy the 7.2.0 (or newer) image your compose file pins, then restart the stack and re-check the running tag. Watch Zammad GitHub security advisories for any follow-up advisory specific to CVE-2026-102490 once Zammad finishes verification.

Until you are on 7.2.0, keep the Zammad UI off the public internet if you can (VPN or allow-listed management network only). That does not fix the LPE once someone is local as zammad, but it cuts the remote half of the chain CISA is tracking.

What this is not

This is not a mass internet worm that needs no user interaction on every Zammad 7.x box. CVE-2026-102489's practical blast is the EOL 6.5 train (and DIVD's stated 6.3.0-before-6.5.4 window). CVE-2026-102490 is local-as-zammad to root, not unauthenticated remote root by itself. It also is not "wait for a detailed Zammad PSIRT write-up before acting": CISA already listed both CVEs with due date 2026-10-05, and Zammad already told admins to move to 7.2.0.

References

Continue reading

All posts