CISA Lists Zammad Vulnerability as Actively Exploited; Chaining Could Lead to Root Access
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the Zammad vulnerability CVE-2026-102489 to its catalog of actively exploited vulnerabilities. Combined with a second flaw, it could allow an attacker to gain root privileges.

CVE-2026-102489 in Zammad was added by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to the Known Exploited Vulnerabilities (KEV) catalog on October 2, 2026. The listing means that CISA has confirmed exploitation of the vulnerability in real-world attacks.
The flaw affects self-hosted deployments of the Zammad help desk and ticketing system. According to the CVE record, it is a session hijacking or session fixation issue that could lead to remote code execution with the privileges of the zammad system user.
CVE-2026-102489 in Zammad could be part of an attack chain
CISA warns that the vulnerability can be chained with CVE-2026-102490. The second flaw is a local privilege escalation from the zammad user to the root user. An attacker who could exploit both flaws could therefore move from remote code execution to complete takeover of the host system.
The risk is particularly relevant for operators of internet-accessible installations. Zammad processes requests from customers and internal users, and tickets may contain attachments, operational information, or credentials. A compromise of the application therefore may not remain limited to the help desk itself.
Affected versions and remediation status
The Dutch DIVD CSIRT record lists Zammad releases from version 6.3.0 through versions before 6.5.4 as affected. For the 7.0.0 through 7.1.3 branch, it records the presence of the flaw but, under the conditions specified in the record, classifies it as not exploitable.
However, the available public materials do not clearly state which specific release fixes the complete CVE-2026-102489 and CVE-2026-102490 chain. Zammad released version 7.2 as early as September 23, 2026, but the release overview itself does not provide clear confirmation that this pair of vulnerabilities was fixed.
Administrators should therefore verify the precise recommended version and remediation procedure directly in the vendor’s security advisory. In its notice, DIVD recommends performing an upgrade or taking the vulnerable system offline if an upgrade is not possible.
CISA’s deadline applies to U.S. federal agencies
CISA set a remediation deadline of October 5, 2026, for U.S. federal civilian agencies. This deadline does not directly apply to private organizations or operators outside the U.S. federal government, but it is another signal of the issue’s severity and confirmed exploitation.
Public materials do not yet contain technical attack details, indicators of compromise, or evidence of a publicly available exploit. The overall scope of attacks against other organizations or the identity of the attackers has also not been independently confirmed.
Zammad operators should monitor the vendor’s detailed advisory, any indicators of compromise from CISA or national CSIRT teams, and updates to CVE records concerning the affected versions and patches.
Sources
- CISA Known Exploited Vulnerabilities Catalog – Confirms that CVE-2026-102489 was added to KEV on October 2, 2026, its active exploitation, the possibility of chaining it with CVE-2026-102490, and the required measures.
- DIVD CSIRT – DIVD-2026-00015 – Describes both vulnerabilities, their possible chaining, affected versions, and the recommendation to upgrade or take the system offline.
- NIST National Vulnerability Database – Corroborates the CVE description, listed affected versions, and the status of its inclusion in the CISA KEV catalog.
- Zammad Releases – Confirms that Zammad released version 7.2 on September 23, 2026, but does not clearly confirm a fix for this pair of CVEs.
Verified and updated: 10/03/2026 06:19



