Vulnerabilities · 5h ago

Zammad Chain Left Root Access Open

NCSC-NL and DIVD say two Zammad zero-days were chained in an active breach, with exploitation underway since 21 September 2026. One flaw, CVE-2026-102489, lets an unauthenticated remote attacker run code in Zammad 6.3.0 through 6.5.4; the second, CVE-2026-102490, turns low privileges into root on the host.

That combination matters because the first bug gets code running and the second raises it to full system control. DIVD says the chain let attackers hijack sessions, execute code, and reach root quickly, then read and exfiltrate data from connected services.

The lasting exposure is on any self-hosted Zammad instance that stays on the vulnerable major line: fixing only the disclosed RCE still leaves a route from help desk access to host takeover. For teams that use ticketing systems as a bridge into internal services, the trust boundary sits in the help desk layer itself.

CVE-2026-102489

NVD KEV

CVE-2026-102490

NVD KEV

Timeline

Sources

3 sources covering this story

Entities

Part of the PlainSec briefing for 2026-09-30

Editions

Related stories