Zammad Zero-Day Flaws Gave Hackers Root Access at DIVD

Zammad zero-day flaws chained together to take over a support server, with CVE-2026-102489 Zammad session hijack leading to root access

Two Unknown Bugs Became Full Server Control

Two unknown vulnerabilities turned the Zammad support system into an entry point with full control of the server. The Dutch Institute for Vulnerability Disclosure (DIVD) revealed the attack in its DIVD case record.

On September 21, attackers broke into its infrastructure through a chain of zero-days. Within seconds, they moved from session hijacking to code execution. Then they gained root rights.

The First Flaw: CVE-2026-102489

The first bug, CVE-2026-102489, allows session hijacking. It also allows remote code execution as the system user zammad. DIVD rated it 8.7 on CVSS 4.0.

The CVE record lists versions from 6.3.0 up to, but not including, 6.5.4 as vulnerable. Attackers need no pre-obtained account.

The faulty code also exists in Zammad 7.0.0 through 7.1.3. However, under normal conditions, exploitation does not work there.

The Second Flaw: CVE-2026-102490

The second zero-day, CVE-2026-102490, works after the break-in. It lets the local user zammad raise privileges to root. It scored 8.5 on CVSS 4.0 and affects versions from 1.5.0 to 7.1.0-alpha.

On its own, this flaw needs local access with low rights. When combined, however, the two problems change the picture. DIVD raises the rating of the whole chain to a critical 9.4 on CVSS 4.0.

Speed Driven by Agentic AI

DIVD links the speed of the attack to agentic AI. In the logs, the organization saw scripts in which an agent explained its own actions. The agent also chose its next steps by itself.

Automation let the attackers run the chain in seconds. After gaining root, they reached other services and began to pull out data. Network segmentation and access blocks finally halted further movement.

What the Breach Exposed

The investigation confirmed a leak of volunteers’ email addresses. Some contact data may also have leaked.

Signs of compromise also appeared in Jira, Confluence, internal service systems, and CSIRT tickets. Zammad carried correspondence about vulnerabilities, IP addresses of problem systems, and fragments of leaked credentials. Therefore, investigators are still establishing the exact amount of stolen data.

Why the Combination Matters

The main danger lies in the combination of bugs. The first gap gives code execution with limited rights. The second needs local access. Together, however, the limits vanish.

A similar chain of flaws has led to root in server products before. In Zammad’s case, the local bug becomes the second stage of a remote server takeover.

How to Protect Zammad Installations

DIVD advises Zammad owners to move to version 7. If an update is not yet possible, they should take the system off the network.

The incident record marks a fix as available. No ready workaround exists. The organization has also released a script that checks logs for indicators of compromise. It continues to warn owners of vulnerable installations that face the internet.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply