HomeCyber BalkansZammad Vulnerabilities Enable Attackers to Execute Code and Escalate Privileges to Root

Zammad Vulnerabilities Enable Attackers to Execute Code and Escalate Privileges to Root

Published on

spot_img

Critical Vulnerabilities Found in Zammad Helpdesk Platform: Urgent Response Required

Recent security findings have unveiled two significant vulnerabilities in the open-source Zammad helpdesk and ticketing platform. These vulnerabilities, classified as CVE-2026-102489 and CVE-2026-102490, have raised alarms among cybersecurity experts. When exploited in tandem, these flaws can allow attackers to achieve remote code execution, effectively granting them root-level control over affected servers. Such a severe breach poses a substantial threat to organizations that rely on this platform for managing their customer support processes.

The vulnerabilities were discovered by the Dutch Institute for Vulnerability Disclosure (DIVD) in collaboration with Merlon Security. Their investigation began following a security breach of DIVD’s own infrastructure, highlighting the risks associated with open-source software that many organizations utilize without adequate scrutiny.

Overview of the Vulnerabilities

In an advisory issued by DIVD, designated as DIVD-2026-00015, the researchers detailed an attack chain that commenced with a session-hijacking issue within Zammad and progressed to local privilege escalation leading to root access. This set of vulnerabilities appears to have been exploited during a cyber intrusion on September 21, 2026, which allowed attackers to compromise the Zammad service account, thereby accessing additional services. Notably, the attackers could potentially read or exfiltrate sensitive information, compounding the seriousness of this security breach. The speed of the attack was alarming, reportedly taking just seconds, a fact that researchers attribute to an advanced, AI-powered attack workflow.

CVE-2026-102489 specifically impacts Zammad versions 6.3.0 through 6.5.4. This vulnerability enables session hijacking, which can result in remote code execution under the permissions assigned to the Zammad service user. Once an attacker successfully acquires a valid session, they can execute commands on the host system, effectively gaining access to critical components such as application files, databases, logs, secrets, and other internal services fundamental to ticketing operations.

DIVD has noted that the vulnerable code also exists in Zammad versions 7.0.0 through 7.1.3; however, the organization stated that these later versions are not exploitable due to certain environmental conditions. Zammad developers have clarified that exploitation is primarily limited to older installations (6.5 and earlier) due to their specific runtime environments. Mitigations for affected code are said to be included in Zammad version 7.2.0. Despite these assurances, Zammad emphasizes that organizations should not delay upgrades, as exposed legacy installations represent a serious ongoing risk.

Understanding the Implications of CVE-2026-102490

The second vulnerability, CVE-2026-102490, reveals a local privilege escalation flaw affecting Zammad versions 1.5.0 through 7.1.0-alpha, including the latest alpha builds mentioned in DIVD’s disclosure. Once an attacker achieves command execution as the local Zammad user through the preceding vulnerability, they can exploit this to escalate their privileges to root level. This escalation effectively transforms an application compromise into a full operating system compromise, allowing the malicious actor to install persistence mechanisms, tamper with logs, access local user data, and pivot into connected infrastructure.

The combination of these two vulnerabilities presents a heightened level of danger, particularly in their effectiveness when used together. CVE-2026-102489 provides a pathway for remote access to vulnerable 6.x systems, whereas CVE-2026-102490 removes the normal privilege boundaries that would limit the potential damage from an application compromise. Both vulnerabilities carry a CVSS score of 9.4 when assessed within this chained-attack scenario, indicating the need for immediate action.

Recommended Actions for Organizations

In light of these alarming vulnerabilities, DIVD urges all Zammad users to upgrade to version 7 or, if immediate upgrades are impossible, take affected instances offline. Administrators managing Zammad versions 6.3.0 through 6.5.4 should view the situation as urgent. Precautionary measures recommended by DIVD include preserving application, web server, authentication, and system logs before implementing remediation strategies, restricting public access to the service, rotation of potentially compromised credentials, and thorough investigation of any unauthorized session activity and command execution.

Furthermore, DIVD has released an Indicators of Compromise (IoC) log-check script specifically for CVE-2026-102489 and is actively scanning for vulnerable public instances, reaching out to owners of affected systems to notify them of the risks.

This incident highlights the need for proactive security measures in the realm of open-source software. As organizations increasingly rely on these platforms for customer engagement and service management, ensuring robust security practices is crucial to mitigating the risks posed by vulnerabilities like those found in Zammad.

Source link

Latest articles

Google Launches Gemini 4 Argon AI Model

Google Unveils Gemini 4 Argon: A New Frontier in Specialized AI for Cybersecurity and...

Dubai Government Agencies Face Off in Hacking Contest

Training & Security Leadership Live And IRL Hacking Contest Captured Attention...

Armadin Secures $255.5 Million Series B for Autonomous Remediation Efforts

Company Plans to Extend Compensating Controls Across MDR and WAF Platforms A notable development in...

Shadow AI and the Permissions Dilemma: What to Consider Before Granting Access to AI

The Rise of AI and the Urgent Need for Caution AI tools have transitioned from...

More like this

Google Launches Gemini 4 Argon AI Model

Google Unveils Gemini 4 Argon: A New Frontier in Specialized AI for Cybersecurity and...

Dubai Government Agencies Face Off in Hacking Contest

Training & Security Leadership Live And IRL Hacking Contest Captured Attention...

Armadin Secures $255.5 Million Series B for Autonomous Remediation Efforts

Company Plans to Extend Compensating Controls Across MDR and WAF Platforms A notable development in...