Zammad Helpdesk Session Fixation Remote Code Execution and Local Privilege Escalation Vulnerabilities

Release Date: 2nd October 2026 (Added 6th October 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-102489 is a session fixation vulnerability (CWE-384) in the Zammad open-source helpdesk and ticketing platform that can lead to remote code execution as the zammad service user. It is rated CVSS 9.8 (Critical) by NVD and needs no authentication.

CVE-2026-102490 is an improper privilege management vulnerability (CWE-269) that lets an attacker who already runs code as the zammad user escalate to root on the server. The two were found by the Dutch Institute for Vulnerability Disclosure (DIVD, case DIVD-2026-00015) and work as a chain: the first gives remote code execution, the second gives full control of the host.

Reference

  1. https://zammad.com/en/advisories/cve-2026-102489-cve-2026-102490
  2. https://community.zammad.org/t/zammad-security-update-on-divd-case-divd-2026-00015-cve-2026-102489-cve-2026-102490/21312
  3. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  4. https://nvd.nist.gov/vuln/detail/CVE-2026-102489
  5. https://nvd.nist.gov/vuln/detail/CVE-2026-102490