Vulnerability  ·  2026-10-03

Zammad session-fixation + local privilege escalation chain (KEV, actively exploited) — the pair an autonomous AI agent used to breach DIVD to root

VulnerabilityHigh impactGlobalCVE-2026-102489
CISA added CVE-2026-102489 (session fixation → RCE as zammad user, CVSS 9.8/9.4, SSVC exploitation=active) and CVE-2026-102490 (local privilege management, zammad→root) to the KEV catalog on 2026-10-02 with confirmed in-the-wild exploitation. Zammad's official statement (2026-10-01) confirms 6.3.0–6.5.4 are affected, states 7.0–7.1.3 carry the code but is not practicable to exploit, hardening is included in 7.2.0, and that DIVD has not yet provided details for 102490.
These are the exact two vulnerabilities chained by an autonomous AI-driven agent to breach the DIVD vulnerability-disclosure nonprofit to root in seconds (DIVD-2026-00015, prior digest). The in-window KEV listing is the operational confirmation that the Zammad chain is being actively exploited in the wild (reported as actively exploited per Zammad's community post), and it is the documented end-to-end example of an AI agent weaponizing a real attacker toolchain against a real target — the pattern defenders must assume applies to their own AI-agent and helpdesk infrastructure.
CVE-2026-102489 is a session-fixation flaw allowing session hijack that leads to remote code execution as the zammad user; CVE-2026-102490 is a local privilege escalation from the zammad user to root. The pair can be chained to full host compromise, and was publicly documented (DIVD DIVD-2026-00015) as the chain executed by a breach that reached root in seconds.
Zammad helpdesk 6.3.0 – 6.5.4 (session fixation, CVE-2026-102489) chained with CVE-2026-102490 (improper privilege management, local zammad→root); fixed in Zammad 7.2.0
Update to Zammad 7.2.0; if still on Zammad 6.5 or older (EOL), upgrade immediately as those versions no longer receive fixes. Follow zammad/zammad GitHub security advisories for CVE-2026-102490 (details not yet shared with vendor at the time of the vendor statement). KEV required action per BOD 26-04, federal due 2026-10-05.
NVD CVE-2026-102489Zammad official statement on DIVD case DIVD-2026-00015CISA KEV catalogDIVD case DIVD-2026-00015
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →