← Back to feed
Vulnerabilities & PatchesEmerging1 sourceOct 2, 2026 · 11:44via CyberPress

Zammad Vulnerabilities Enable Remote Code Execution and Root Privilege Escalation

Brief

Two newly disclosed vulnerabilities in the Zammad open-source helpdesk platform could let attackers achieve remote code execution and then escalate to root on affected servers.

DIVD CSIRT identified the flaws, tracked as CVE-2026-102489 and CVE-2026-102490, during its investigation into a separate security incident involving the organization.

DIVD said the vulnerabilities were actively abused on September 21, 2026, to breach its own environment. Its researchers subsequently analyzed and reproduced the attack chain before reporting the findings to Zammad on September 24.

Zammad Vulnerabilities

CVE-2026-102489 affects Zammad versions 6.

  • 0 through 6.
  • 4 and involves a session-hijacking issue that can result in remote code execution under the zammad user account.
Read more on CyberPress→