XHack Logo
XHack
Products
Services
Compliance
Pricing
Resources
Company
Sign upLogin
XHack Logo
XHackOffensive Security

Certified offensive security team delivering penetration testing evidence written for your auditor.

OSCP+OSCPC-AI/MLPenCASA
support@xhack.io

24/7 SOC Operations

XHack Status
Under attack? Get help now
Services
  • VAPT Services
  • Red Teaming
  • SOC Services
  • Threat Intelligence
  • Incident Response
  • Managed Testing
Pricing
  • Platform Plans
  • Services Pricing
Compliance
  • SOC 2
  • PCI DSS
  • ISO 27001
  • GDPR
  • HIPAA
  • ISO 42001
  • AI Maturity Assessment
  • TX-RAMP
  • NBFC / SECP
  • All Frameworks
Products
  • Vulnerability Assessment
  • GitGuard
  • AI Probe
  • SOC Dashboard
  • AI Agent
  • Cloud Investigation
Comparison
  • XBOW vs XHack
  • Horizon3 vs XHack
  • Strix vs XHack
  • Pentera vs XHack
Resources
  • Platform Tour
  • All Features
  • Install the Agent
  • XHack AI
  • Documentation
  • Blog
  • Case Studies
  • Documents
  • FAQ
Company
  • About Us
  • Our Team
  • Certifications
  • Security and Trust
  • VAPT Explained
  • Contact

© 2026 XHack. All rights reserved.

Security & TrustVulnerability DisclosurePrivacy PolicyTerms of ServiceRefund Policy
Blog/News

CVE-2026-102489: How a Critical Zammad Chain Gave an Attacker Root in Seconds

XHack

XHack

Author

October 2, 2026

13 min read

CVE-2026-102489: How a Critical Zammad Chain Gave an Attacker Root in Seconds

Table of contents

20

What Zammad Is, and Why a Helpdesk Is a Good Target

What CVE-2026-102489 and CVE-2026-102490 Are

How the Chain Works, and What Is Actually Public

What DIVD’s Detection Script Reveals

Why We’re Not Showing You Vulnerable Code

The Dispute Between DIVD and Zammad

The AI-Agent Claim: What DIVD Actually Observed

Are You Exposed to CVE-2026-102489?

Fixing CVE-2026-102489

Hunting for CVE-2026-102489 Compromise

How XHack Reads CVE-2026-102489

FAQ: CVE-2026-102489 Questions Answered

What is CVE-2026-102489?

Is CVE-2026-102489 being exploited?

What is CVE-2026-102490?

How do I fix CVE-2026-102489?

Which Zammad versions does CVE-2026-102489 affect?

Is there a patch for CVE-2026-102490?

Did an AI agent really hack DIVD?

The Bottom Line

Read this in 30 seconds: CVE-2026-102489 and CVE-2026-102490 are two Zammad helpdesk bugs that chain from a remote session hijack to root, and CISA says both are being exploited.

  • The chain is two bugs. CVE-2026-102489 is a session hijack that leads to code execution as the zammad user, with no login. CVE-2026-102490 is a local escalation from that user to root.
  • We know about it because a security nonprofit got breached. The Dutch Institute for Vulnerability Disclosure (DIVD) says an attacker used the chain against its own Zammad on September 21, and that the intrusion looked like an autonomous AI agent.
  • The technical details are withheld. DIVD hasn’t published how either bug works, and we couldn’t find the fix in Zammad’s public code, so this article doesn’t pretend to show you vulnerable code.
  • The vendor and the finder disagree. On which versions are exposed, on disclosure timing, and on whether CVE-2026-102490 is confirmed at all.
  • Safest move: upgrade to Zammad 7.2.0, then hunt. CISA added both CVEs to KEV on October 2 with a three-day deadline and a forensic-triage flag.

A helpdesk is where a company keeps its customers’ complaints, contracts and credentials, and a two-bug chain that reaches root there turns a support queue into a foothold.

CVE-2026-102489 was published on September 30, 2026, by DIVD, the same organization that found it by reverse engineering an attack on itself. CISA added it and its companion to the Known Exploited Vulnerabilities catalog two days later, with a due date of October 5.

Here’s what’s actually public about CVE-2026-102489, where the sources contradict each other, and what to check on your own Zammad.

CVE-2026-102489 and CVE-2026-102490 severity summary: a two-bug Zammad chain from remote session hijack to code execution as the zammad user to root, added to CISA KEV October 2 2026, NVD CVSS 9.8 each
CVE-2026-102489 at a glance: a remote session hijack, then a local jump to root

What Zammad Is, and Why a Helpdesk Is a Good Target

Zammad is an open-source ticketing and helpdesk platform, available self-hosted or as a service. Teams run it for customer support and IT service desks, and per Sysdig’s analysis DIVD used it for CSIRT ticketing. That means its database holds customer messages, attachments, contact details and often the integrations that connect to mail, chat and other systems.

A foothold there is worth more than the product’s size suggests. An attacker who lands on the Zammad host can read everything agents can read, and anything else the server can reach.

What CVE-2026-102489 and CVE-2026-102490 Are

CVE-2026-102489 and its companion are separate bugs that DIVD and CISA both describe as chainable:

CVE-2026-102489CVE-2026-102490
What it isSession hijack leading to remote code execution as the zammad userLocal privilege escalation from the zammad user to root
CWECWE-384 (session fixation)CWE-269 (improper privilege management)
NeedsNetwork access, no credentialsCode execution on the server already
Affected (NVD)6.3.0 to 6.5.4, plus 7.0.0 to 7.1.31.5.0 up to 7.1.0, plus the 7.1.0 alpha
Fix statusZammad says hardened in 7.2.0No fix identified

Both carry an NVD CVSS 3.1 score of 9.8 (AV:N/AC:L/PR:N/UI:N), and DIVD’s own CVSS 4.0 vector scores both 9.4. Those two numbers describe the chain, not the second bug alone.

That’s worth saying out loud, because CVE-2026-102490 is a local bug. Zammad’s fliebe92, posting on its community forum, states it plainly: “This issue cannot be exploited remotely on its own. An attacker would already need access to your server.” A 9.8 on a bug that needs prior code execution only makes sense as a chain score.

CISA’s SSVC data adds one more signal: active exploitation, with CVE-2026-102489 marked automatable. CVE-2026-102490 is not, which fits a bug that only matters after the first one lands.

How the Chain Works, and What Is Actually Public

Here’s the part to be precise about, because most coverage isn’t. No source has published the mechanism of CVE-2026-102489 or its companion. DIVD’s case page describes CVE-2026-102489 only as a “session hijack vulnerability that leads to remote code execution as the zammad user,” and the CVE record repeats that sentence. CVE-2026-102490 is described in one line.

What the sources do confirm, from DIVD and from Sysdig’s analysis of it:

  • The attacker reached code execution as the zammad service user through the session bug, with no credentials.
  • The attacker then used the second bug to reach root, which DIVD says took seconds.
  • After that came password spraying, access to other services, and data exfiltration, including volunteer email addresses.

There’s one more clue, and it’s a small one. DIVD’s CVSS 4.0 vector for CVE-2026-102489 includes UI:P, passive user interaction. That would fit a session-fixation flaw, where the victim’s own login completes the attack. But that’s our reading of one metric, not something DIVD has stated.

What DIVD’s Detection Script Reveals

The most revealing artifact is DIVD’s IOC check script. Its core is a single search over Zammad and nginx logs:

zgrep -En 'ERROR -- :.*("Cookie"=>"|@clients=\{)' /var/log/zammad/* /var/log/nginx/*

It looks in production.log, railsserver.log, websocket.log, scheduler.log and the nginx logs for error lines that contain cookie values or what looks like websocket client state. Matches mean session material is showing up in error output.

We don’t know from the script alone why exploitation leaves that trace. A reasonable guess is that the attack path triggers an error that dumps request headers and connection state into the logs. That’s inference from what the script searches for, not something DIVD has said.

Why We’re Not Showing You Vulnerable Code

Zammad is open source, so we looked. We pulled Zammad’s public history between 7.1.3 and 7.2.0, 241 commits, and found nothing identifiable as the fix. 7.2.0’s release commit is dated September 23, and Zammad says the change is in that release.

One nearby commit is easy to mistake for it. An October 1 change to Zammad’s file session store is a race-condition fix for websocket sessions getting lost on login. It is a reliability fix, not the security patch, and treating it as one would be a guess.

So we’re not going to reconstruct code for a bug nobody has described. If DIVD or Zammad publishes the mechanism, this section is the one that changes.

What is public about CVE-2026-102489 and what is withheld: the confirmed chain and exploitation facts on one side, the unpublished mechanism, fix commit, scope of CVE-2026-102490 and attacker identity on the other, plus DIVD's log search
CVE-2026-102489: what we can and can’t say

The Dispute Between DIVD and Zammad

The disclosure of CVE-2026-102489 is unusually messy, and the disagreement matters for what you do next.

QuestionDIVDZammad
Is Zammad 7.x exposed to CVE-2026-102489?Present in 7.0.0 to 7.1.3 but “not exploitable due to environment conditions”“Zammad 7.0 and later are not affected”
What should you upgrade to?“Version 7 of Zammad or to take it offline”7.2.0, the current stable release
Is CVE-2026-102490 confirmed?Affects all versions, including the latest alpha“We cannot confirm the vulnerability, its scope or the affected versions”
DisclosureReported September 24, public scanning and disclosure September 26DIVD gave no technical details on CVE-2026-102490, yet a CVE ID was published for it

Zammad’s staff add two facts of their own. They say they first received a report about the session issue in August 2026 and analyzed it then, and that the fix shipped in 7.2.0, whose release commit predates DIVD’s September 24 report. DIVD’s attack on September 21 happened before 7.2.0 existed.

Read together, the sources agree on the practical answer even where they disagree on the details. Versions 6.5.4 and older are exploitable for CVE-2026-102489. Anything on 7.x is either unaffected or not exploitable. 7.2.0 satisfies everyone’s guidance.

Which Zammad version is exposed to CVE-2026-102489 and CVE-2026-102490: 6.5.4 and older exploitable, 7.0 to 7.1.3 present but not exploitable according to DIVD or unaffected according to Zammad, 7.2.0 hardened, and no fix identified for the root escalation
Which Zammad version is exposed: where DIVD, NVD and Zammad agree and disagree

The AI-Agent Claim: What DIVD Actually Observed

DIVD’s headline claim is that an autonomous AI agent ran the intrusion. The evidence it offers is behavioral. The agent was “loud and very messy,” decided each next step itself at machine speed, and left comments in its own scripts explaining why what it was doing was acceptable, which DIVD says a human attacker wouldn’t bother to write.

That’s DIVD’s assessment, and Sysdig’s analysis calls it inferred from operational patterns rather than from any attribution. Nobody has identified who or what was behind it.

The defensive takeaway doesn’t depend on settling that. The chain went from no credentials to root in seconds, and the first sign of trouble was a messy intrusion DIVD noticed the next day. When both bugs are available, a defender has no window to react between the stages, so the controls that matter are the ones already in place: patching, segmentation and logging. We cover the offensive side in our piece on autonomous AI hacking agents.

Are You Exposed to CVE-2026-102489?

You’re exposed if both of these are true:

  1. You run Zammad 6.5.4 or older, back to 6.3.0. That’s the range everyone agrees is exploitable. If you’re on 7.0.0 to 7.1.3, DIVD says the flaw exists but can’t currently be exploited, and Zammad says you’re unaffected.
  2. Your Zammad is reachable by an attacker. CVE-2026-102489 needs no credentials, only network access to the web interface.

CVE-2026-102490 is a different question: it needs code execution first, so it only matters after the first bug or any other foothold.

Fixing CVE-2026-102489

  1. Upgrade to Zammad 7.2.0. It’s Zammad’s recommendation and it satisfies DIVD’s “version 7” guidance. If you’re on 6.5 or older, do this now.
  2. If you can’t upgrade today, take Zammad offline. That’s DIVD’s advice, and it’s the only mitigation either source offers.
  3. Assume there’s no patch for CVE-2026-102490. DIVD says it affects every version; Zammad says it can’t confirm it. Until that’s resolved, the practical control is limiting what a compromised zammad user can reach.
  4. Contain the blast radius. DIVD credits network segmentation with stopping the attacker from going deeper. Running Zammad in a container without host access, and restricting its outbound traffic, are our own suggestions, not vendor guidance.
  5. Then hunt. CISA’s forensic-triage flag means checking for prior compromise, not just patching.

Hunting for CVE-2026-102489 Compromise

Start with DIVD’s search for CVE-2026-102489 above. Then use Sysdig’s detection guidance for each stage of the chain:

  • Shells or unexpected child processes spawned by Zammad’s processes, and downloads or outbound connections from the Zammad host that you can’t explain.
  • Setuid-family calls from the zammad user, new root-owned child processes under the application tree, and writes to privileged paths by that account.
  • Mass reads of configuration and credential files, and bursts of failed logins against many accounts.
  • Outbound connections from the helpdesk network segment to destinations it has never contacted, and large or unusual uploads.
  • A session used from a new source address shortly after login. Sysdig points to this as a signal for the session-hijack stage.

If anything matches, treat it as confirmed compromise. Preserve /var/log/zammad and /var/log/nginx before you rebuild anything, since CISA’s forensic-triage guidance calls for evidence preservation first. A clean search doesn’t clear you: DIVD’s script only finds one trace of one stage.

How XHack Reads CVE-2026-102489

The lesson in CVE-2026-102489 isn’t the specific flaw, which nobody has described. It’s that session handling and privilege boundaries are two places where bugs chain, and each stage looks modest on its own. A session flaw that yields a service-user shell, plus a local escalation, is a full compromise from two bugs that individually might be triaged as medium.

A pentest that validates chains, not isolated findings, is how you’d find that before an attacker does. We’d test a pre-authentication session for fixation and reuse across login, then ask what a shell as the application user can reach on the host. Our AI VAPT services piece covers how that kind of chained validation works.

The other thing this case shows is why the forensic step matters. We make the same point about the Arista VeloCloud bug CISA also flagged for forensics: patching closes the door, but it doesn’t tell you who already walked through it.

FAQ: CVE-2026-102489 Questions Answered

What is CVE-2026-102489?

CVE-2026-102489 is a Zammad session-fixation vulnerability (CWE-384) that lets an unauthenticated attacker hijack a session and execute code as the zammad service user. It affects Zammad 6.3.0 to 6.5.4, and DIVD says it’s also present but not exploitable in 7.0.0 to 7.1.3. NVD scores it 9.8.

Is CVE-2026-102489 being exploited?

Yes. DIVD says it was used against DIVD itself on September 21, 2026, chained with CVE-2026-102490, and CISA added both to the Known Exploited Vulnerabilities catalog on October 2 with a due date of October 5.

What is CVE-2026-102490?

CVE-2026-102490 is a local privilege escalation that lets the zammad user become root. DIVD says it affects every Zammad version from 1.5.0 through the 7.1.0 alpha. Zammad says it can’t confirm the vulnerability, and that it can’t be exploited remotely on its own.

How do I fix CVE-2026-102489?

Upgrade to Zammad 7.2.0, which Zammad says includes the change that hardens the vulnerable code. If you can’t upgrade, DIVD advises taking Zammad offline. Then check your logs for compromise before assuming the upgrade was enough.

Which Zammad versions does CVE-2026-102489 affect?

NVD lists 6.3.0 through 6.5.4 as exploitable and 7.0.0 through 7.1.3 as affected but, per DIVD, not exploitable. Zammad says 7.0 and later are not affected and that CVE-2026-102489 is only exploitable on 6.5 and older.

Is there a patch for CVE-2026-102490?

We couldn’t identify one. DIVD’s guidance is to upgrade to version 7 or go offline, and neither source offers a specific mitigation for the escalation.

Did an AI agent really hack DIVD?

DIVD says it did, based on how the attacker behaved: machine-speed steps and self-explaining comments in its scripts. Sysdig calls that an inference from operational patterns. No one has publicly attributed the attack.

The Bottom Line

CVE-2026-102489 is a case where the practical advice is clear even though the technical story isn’t. Upgrade to 7.2.0, take Zammad offline if you can’t, and run DIVD’s log search plus Sysdig’s detection list before you decide the upgrade was enough.

What you shouldn’t do is trust any write-up that claims to show you exactly how the bugs work. Nobody has published that yet, including us. When the mechanism does come out, the interesting part will be how a session flaw ended up one local escalation away from root.


Categories

News

Previous

Does AI Actually Help You Win Bug Bounties? The Honest 2026 Answer

Next

How Much Do Bug Bounty Hunters Make in 2026? The Honest Numbers

On this page

What Zammad Is, and Why a Helpdesk Is a Good Target

What CVE-2026-102489 and CVE-2026-102490 Are

How the Chain Works, and What Is Actually Public

What DIVD’s Detection Script Reveals

Why We’re Not Showing You Vulnerable Code

The Dispute Between DIVD and Zammad

The AI-Agent Claim: What DIVD Actually Observed

Are You Exposed to CVE-2026-102489?

Fixing CVE-2026-102489

Hunting for CVE-2026-102489 Compromise

How XHack Reads CVE-2026-102489

FAQ: CVE-2026-102489 Questions Answered

What is CVE-2026-102489?

Is CVE-2026-102489 being exploited?

What is CVE-2026-102490?

How do I fix CVE-2026-102489?

Which Zammad versions does CVE-2026-102489 affect?

Is there a patch for CVE-2026-102490?

Did an AI agent really hack DIVD?

The Bottom Line

Related articles

Continue reading

CVE-2026-82042: The Critical UTMStack Flaw Where One Shared Key Was Admin

News

CVE-2026-82042: The Critical UTMStack Flaw Where One Shared Key Was Admin

CVE-2026-82042 and CVE-2026-82041 are critical UTMStack SIEM flaws: one shared key acted as admin, and no role check gua...

Read article
CVE-2026-104286: The Critical FortiMail Bug That Writes Files Anywhere on Disk

News

CVE-2026-104286: The Critical FortiMail Bug That Writes Files Anywhere on Disk

CVE-2026-104286 is a CVSS 9.8 unauthenticated arbitrary file-write bug in Fortinet FortiMail, actively exploited. Fortin...

Read article
CVE-2026-76504: The Cisco SD-WAN Bug That Admin Logs In With One Encoded Letter

News

CVE-2026-76504: The Cisco SD-WAN Bug That Admin Logs In With One Encoded Letter

CVE-2026-76504 is a CVSS 9.8 unauthenticated admin-access bug in Cisco SD-WAN Manager, actively exploited. It’s th...

Read article