Zammad session fixation to root hits CISA KEV
How to fix CVE-2026-102489: upgrade Zammad to 7.2.0 (leave 6.5 EOL trains; chain with CVE-2026-102490)
Contents
CISA added CVE-2026-102489 and CVE-2026-102490 to the Known Exploited Vulnerabilities catalog today (2026-10-02). The pair is a chain in the open-source Zammad helpdesk: session fixation that can reach remote code execution as the zammad user, then local privilege escalation from that user to root. CISA notes the two can be chained. KEV due date is 2026-10-05. Required action follows BOD 26-04 (risk-based patching plus forensic triage where applicable). Catalog version is 2026.10.02.
DIVD published the CVEs under case DIVD-2026-00015 after investigating its own network breach (case DIVD-2026-00014). DIVD says the chain was used in an automated attack against its Zammad instance. This page is the operator write-up from CISA KEV, the DIVD CVE records, and Zammad's community guidance. The HOL Guard evidence pack for CVE-2026-102489 is the linked source record (sibling CVE-2026-102490).
What breaks
CVE-2026-102489 (session fixation to RCE as zammad): DIVD rates CVSS 4.0 base 8.7 High (critical sibling vector 9.4). Attack vector is network, privileges none, user interaction passive, exploit maturity Attacked. DIVD marks Zammad 6.3.0 through versions before 6.5.4 as affected on Linux/Docker. Versions 7.0.0 and later are listed unaffected for practical exploitation; DIVD and Zammad both say the defect is present on some 7.x trains but not exploitable under those runtime conditions. Zammad states it hardened the code in 7.2.0.
CVE-2026-102490 (local privilege escalation to root): DIVD rates CVSS 4.0 base 8.5 High (critical sibling vector 9.4). Attack vector is local: an attacker who already runs as the zammad OS user can escalate to root. DIVD lists affected from 1.5.0 before 7.1.0-alpha. Zammad's community thread (2026-10-01) says it received technical details from DIVD and is working the fix, and that this issue cannot be exploited remotely on its own. CISA's KEV row explicitly says it can be chained with CVE-2026-102489.
Together: network path into RCE as zammad, then root on the host. That is why CISA put both on KEV the same day with a three-day due date.
Who is not in scope
- Zammad 7.0+ for CVE-2026-102489 exploitation per DIVD product status and Zammad's 2026-10-01 statement: the session-to-RCE path is not practically exploitable on current 7.x runtime. Still upgrade to 7.2.0 for the hardening and for the LPE track.
- Hosts where the attacker cannot reach the Zammad HTTP(S) UI and also cannot obtain a local
zammadshell. The LPE alone is not a remote worm. - Non-Zammad helpdesks (Zendesk, Freshdesk, osTicket, and so on). These CVE IDs are Zammad GmbH Zammad only.
- Cloud SaaS tenants on Zammad's hosted product only if your vendor confirms your tenant train is already on a fixed build. Self-hosted and Docker operators own the upgrade.
One operator check
On each self-hosted box, confirm the installed package version and whether the service is internet-facing:
# Debian/Ubuntu package installs
dpkg -l zammad | awk 'NR==1 || /^ii/'
# RPM installs
rpm -q zammad
# Docker / compose: inspect the image tag you actually run
docker ps --format '{{.Image}}' | grep -i zammad
# Confirm the UI listener is not on the public internet unless required
ss -lntp | egrep ':80|:443'
If dpkg/rpm/docker shows anything older than 7.2.0, schedule the upgrade now. Federal and BOD 26-04 environments also owe forensic triage before they declare the host clean; KEV due date is 2026-10-05.
How to fix
Zammad's public guidance (community thread, 2026-10-01 / 2026-10-01 evening update): update to Zammad 7.2.0, the current stable release. If you still run Zammad 6.5 or older, update now; those trains no longer receive security fixes under Zammad's policy.
# Package-based self-host (follow your distro docs for the Zammad repo)
sudo apt-get update && sudo apt-get install --only-upgrade zammad
# or
sudo yum update zammad
# Then confirm
dpkg -l zammad
# expect 7.2.0 or newer on the Version column
Docker operators: pull and redeploy the 7.2.0 (or newer) image your compose file pins, then restart the stack and re-check the running tag. Watch Zammad GitHub security advisories for any follow-up advisory specific to CVE-2026-102490 once Zammad finishes verification.
Until you are on 7.2.0, keep the Zammad UI off the public internet if you can (VPN or allow-listed management network only). That does not fix the LPE once someone is local as zammad, but it cuts the remote half of the chain CISA is tracking.
What this is not
This is not a mass internet worm that needs no user interaction on every Zammad 7.x box. CVE-2026-102489's practical blast is the EOL 6.5 train (and DIVD's stated 6.3.0-before-6.5.4 window). CVE-2026-102490 is local-as-zammad to root, not unauthenticated remote root by itself. It also is not "wait for a detailed Zammad PSIRT write-up before acting": CISA already listed both CVEs with due date 2026-10-05, and Zammad already told admins to move to 7.2.0.
References
- CISA KEV CVE-2026-102489 (dateAdded 2026-10-02, dueDate 2026-10-05, catalogVersion 2026.10.02)
- CISA KEV CVE-2026-102490
- DIVD CVE-2026-102489
- DIVD CVE-2026-102490
- DIVD-2026-00015
- Zammad community guidance (upgrade to 7.2.0)
- CVE-2026-102489 / CVE-2026-102490
Continue reading
All posts
BREAKING: Unauthenticated NetScaler RCE hits every appliance (CVE-2026-88771)
How to fix CVE-2026-88771: upgrade NetScaler ADC/Gateway to 14.1-73.37 or 13.1-64.23

FortiMail unauthenticated path traversal hits CISA KEV
How to fix CVE-2026-104286: disable FortiMail IBE (config system encryption ibe / set status disable) or upgrade to upcoming 8.0.2 / 7.6.7 / 7.4.9

Cisco SD-WAN Manager admin API bypass hits CISA KEV
How to fix CVE-2026-76504: upgrade Cisco Catalyst SD-WAN Manager to 20.9.10.1 / 20.12.8.2 / 20.15.6.1 / 20.18.4.1 / 26.1.2.1 / 26.2.1
