CISA Warns of Actively Exploited Zammad Vulnerabilities Enabling Full System Takeover
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical Zammad vulnerabilities to its Known Exploited Vulnerabilities catalog, highlighting risks of remote code execution (RCE) and root-level access on vulnerable Linux and Docker deployments. Federal civilian agencies must mitigate or discontinue use of affected versions by October 5, 2026, under Binding Operational Directive (BOD) 26-04.
The flaws, CVE-2026-102489 and CVE-2026-102490, can be chained to compromise systems. The first, a session fixation vulnerability (CVSS v4: 9.4), affects Zammad versions 6.3.0–6.5.4, allowing attackers to hijack sessions and execute code as the low-privileged zammad service account. The second, an improper privilege management flaw, enables local users to escalate privileges to root. CISA confirmed active exploitation of the latter, with reports indicating attackers first gain code execution via CVE-2026-102489 before leveraging CVE-2026-102490 for full server control.
Zammad disputed the practical impact of CVE-2026-102489, stating exploitation is limited to Zammad 6.5 and older due to runtime environment constraints, while Zammad 7.0+ remains unaffected. The company later acknowledged CVE-2026-102490 but noted it requires pre-existing server access. Zammad released version 7.2.0 to address both issues, urging administrators to upgrade and monitor for unauthorized activity.
CISA emphasized that internet-exposed Zammad deployments are high-priority targets, though ransomware use remains unconfirmed. Organizations are advised to conduct forensic triage, review access logs for suspicious zammad account behavior, and investigate root-level processes before restoring systems to normal operation.
Source: https://cyberpress.org/cisa-warns-of-zammad-privilege-escalation-vulnerability/
Zammad TPRM report: https://www.rankiteo.com/company/zammad
"id": "zam1791188646",
"linkid": "zammad",
"type": "Vulnerability",
"date": "10/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Organizations using Zammad '
'versions 6.3.0–6.5.4',
'industry': 'Customer Support/IT',
'name': 'Zammad',
'type': 'Software Vendor'}],
'attack_vector': 'Remote',
'customer_advisories': 'Organizations are advised to upgrade to Zammad 7.2.0 '
'and monitor for unauthorized activity.',
'description': 'The U.S. Cybersecurity and Infrastructure Security Agency '
'(CISA) has added two critical Zammad vulnerabilities to its '
'Known Exploited Vulnerabilities catalog, highlighting risks '
'of remote code execution (RCE) and root-level access on '
'vulnerable Linux and Docker deployments. The flaws, '
'CVE-2026-102489 and CVE-2026-102490, can be chained to '
'compromise systems. CVE-2026-102489 is a session fixation '
'vulnerability (CVSS v4: 9.4) allowing attackers to hijack '
"sessions and execute code as the low-privileged 'zammad' "
'service account. CVE-2026-102490 is an improper privilege '
'management flaw enabling local users to escalate privileges '
'to root. Active exploitation of the latter has been '
'confirmed.',
'impact': {'operational_impact': 'Full system takeover, root-level access',
'systems_affected': 'Linux and Docker deployments of Zammad '
'versions 6.3.0–6.5.4'},
'post_incident_analysis': {'corrective_actions': 'Upgrade to Zammad 7.2.0, '
'monitor for unauthorized '
'activity, conduct forensic '
'triage',
'root_causes': 'Session fixation vulnerability '
'(CVE-2026-102489) and improper '
'privilege management flaw '
'(CVE-2026-102490)'},
'recommendations': 'Upgrade to Zammad version 7.2.0, monitor for unauthorized '
'activity, conduct forensic triage, review access logs for '
'suspicious behavior, investigate root-level processes '
'before restoring systems.',
'references': [{'source': 'CISA Known Exploited Vulnerabilities Catalog'}],
'regulatory_compliance': {'regulations_violated': 'Binding Operational '
'Directive (BOD) 26-04 (for '
'federal civilian agencies)',
'regulatory_notifications': 'CISA Known Exploited '
'Vulnerabilities '
'catalog'},
'response': {'containment_measures': 'Upgrade to Zammad version 7.2.0, '
'monitor for unauthorized activity, '
'conduct forensic triage, review access '
"logs for suspicious 'zammad' account "
'behavior, investigate root-level '
'processes',
'enhanced_monitoring': 'Monitor for unauthorized activity, '
'review access logs',
'recovery_measures': 'Restore systems to normal operation after '
'investigation',
'remediation_measures': 'Upgrade to Zammad version 7.2.0'},
'stakeholder_advisories': 'Federal civilian agencies must mitigate or '
'discontinue use of affected versions by October 5, '
'2026.',
'title': 'CISA Warns of Actively Exploited Zammad Vulnerabilities Enabling '
'Full System Takeover',
'type': 'Vulnerability Exploitation',
'vulnerability_exploited': ['CVE-2026-102489', 'CVE-2026-102490']}