Zammad Helpdesk Session Fixation Remote Code Execution and Local Privilege Escalation Vulnerabilities
Release Date: 2nd October 2026 (Added 6th October 2026)
Impact : CRITICAL
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-102489 is a session fixation vulnerability (CWE-384) in the Zammad open-source helpdesk and ticketing platform that can lead to remote code execution as the zammad service user. It is rated CVSS 9.8 (Critical) by NVD and needs no authentication.
CVE-2026-102490 is an improper privilege management vulnerability (CWE-269) that lets an attacker who already runs code as the zammad user escalate to root on the server. The two were found by the Dutch Institute for Vulnerability Disclosure (DIVD, case DIVD-2026-00015) and work as a chain: the first gives remote code execution, the second gives full control of the host.
What are the systems affected?
The following Zammad versions are affected, with the disagreements between sources taken into account:
CVE-2026-102489: Zammad 6.3.0 to 6.5.4 (exploitable per all sources); Zammad 6.5 and earlier are no longer supported; 7.0.0 to 7.1.3 are listed by NVD only and treated as at risk until confirmed – (Affected)
CVE-2026-102490: Zammad 1.5.0 to 7.1.0-alpha per NVD and DIVD, which includes the latest alpha; installations packaged with packager.io are the ones Zammad links to the flaw – (Affected)
Not affected / patched version:
CVE-2026-102489: Zammad 7.2.0 or later, which includes hardening for this issue – (Not affected)
CVE-2026-102490: no confirmed fix at the time of writing. Zammad 7.2.0 is the recommended current release, but it has not been confirmed to remove this flaw, so check Zammad's security advisories and GitHub for the patch
What does this mean?
Successful exploitation may allow attackers to:
- Take over a Zammad session and run code on the server as the zammad user, without credentials (CVE-2026-102489)
- Escalate from the zammad user to root and take full control of the host (CVE-2026-102490)
- Read or alter every ticket, customer record and attachment held in the helpdesk, and use the server as a foothold for further attacks
Mitigation process?
CERTVU recommends the following:
-
Upgrade Immediately
Upgrade Zammad to 7.2.0 or later. Versions 6.5 and earlier are unsupported, so plan a full upgrade rather than a patch. If an upgrade is not possible straight away, take the instance offline or remove it from the internet. -
Limit Access to the Server
-
Watch for the CVE-2026-102490 Fix
-
Check for Compromise
Reference
- https://zammad.com/en/advisories/cve-2026-102489-cve-2026-102490
- https://community.zammad.org/t/zammad-security-update-on-divd-case-divd-2026-00015-cve-2026-102489-cve-2026-102490/21312
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-102489
- https://nvd.nist.gov/vuln/detail/CVE-2026-102490
- Download advisory (English): Zammad Helpdesk Session Fixation RCE and Local Privilege Escalation Vulnerabilities