SecuFocus
BriefAnnouncements

Exposed Zammad: two flaws, no announced fix

On 2 October 2026, CISA added CVE-2026-102489 and CVE-2026-102490. One can run code remotely. The other can turn a local zammad user into root. DIVD advises version 7 or taking the instance offline, and says Zammad is still working on a fix.

Illustration, not a Zammad screenshot.

Original AI-generated illustration · SecuFocus

At a glance

Key points

The catalog says exploited. It does not name a release that closes both flaws.

What changed

On 2 October 2026, CISA added two Zammad flaws to its catalog, based on evidence of exploitation. CVE-2026-102489 is a session fixation bug that can lead to remote code execution as the zammad user. CVE-2026-102490 can then let that local user become root. CISA sets 5 October 2026 as the due date for U.S. federal civilian agencies. That date does not bind other organisations. It does say the window is short.

The version ranges, kept separate

DIVD case DIVD-2026-00015, updated on 1 October 2026, splits the ranges. For remote code execution: versions 6.3.0 to 6.5.4. Versions 7.0.0 to 7.1.3 contain the flaw, but DIVD says it is not exploitable because of environment conditions. For the local privilege escalation: 1.5.0 to 7.1.0-alpha, including the latest alpha. NVD, whose record was modified on 3 October 2026, repeats the same bounds.

DIVD advises upgrading to version 7, or taking the instance off the network. The same case says the flaw was reported to Zammad, which is working on a fix. Moving to version 7 does not, on this reading, close the local escalation described through 7.1.0-alpha.

What we did not check

We did not install Zammad, and we did not search a log for traces. “Exploited” comes from CISA. The ranges come from DIVD and NVD, not from a SecuFocus test. The Zammad release notes page, opened on 3 October 2026, did not name these CVEs. A forum post is not the vendor advisory.

The choice

If the instance can be reached from the Internet, take it off the network or follow the DIVD case, then reread that case before calling a version safe. The CISA catalog does not replace it.

Check and explore

Sources for this article

Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.

  1. NVD, CVE-2026-102489 ↗nvd.nist.gov ·
  2. NVD, CVE-2026-102490 ↗nvd.nist.gov ·

This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.

Cite this article

Keep this reference with the article when you save or share it.