Session Hijacking as a Beachhead: CVE-2026-102489 and the Zammad Root Chain
Vulnerability overview
Session hijacking rarely reads as a critical finding on its own. In the Zammad attack on DIVD, it was the door. CVE-2026-102489 turns a hijacked session into remote code execution as the zammad user, and CVE-2026-102490 then lifts that account to root. The chain is rated 9.4, Critical, on CVSS 4.0, with both flaws marked as exploited in the wild.
Mechanism and exploitation conditions
The first stage is reachable without credentials. CVE-2026-102489 requires no privileges and only some passive user interaction, and its standalone score is 8.7. It lands the attacker inside the application's own service account. That is a modest position on its own — the zammad user is deliberately unprivileged — which is exactly why the second stage exists.
CVE-2026-102490 converts that local foothold into root, scoring 8.5 alone precisely because local access is a precondition. Neither the vendor nor DIVD has published the underlying defect for either stage, so defenders should reason from preconditions rather than from speculation about memory layout or logic errors. What is documented is the sequence and its speed: DIVD reports the chain was automatable and that root arrived in seconds.
Impact
The combined effect is worth spelling out because the halves understate it. An unauthenticated network attacker gains full control of the server. From there, ticket data, chat history and customer records are readable, configuration secrets are harvestable, and the host becomes a pivot point. DIVD confirmed volunteer data was taken, including email addresses and possibly contact details, and warned about impersonation risk.
Affected products and scope
CVE-2026-102489 is exploitable on Zammad 6.3.0 to 6.5.4, while 7.0.0 to 7.1.3 carries the bug but is assessed as not exploitable because of environment conditions. CVE-2026-102490 covers Zammad 1.5.0 to the 7.1.0 alpha. Linux and Docker deployments are affected.
Exposure context
A ZoomEye search for app="Zammad" returned 11,977 instances at collection time (2026-10-02T06:12:32Z). This is product-fingerprint exposure rather than a count of confirmed vulnerable hosts, and a vul.cve filter for CVE-2026-102490 produced no indexed results.
Remediation and mitigations
DIVD advises upgrading to Zammad version 7 or taking the system offline, which removes the remote entry point and breaks the chain. The escalation flaw remains in current releases with a fix in progress. Run the published log check script against Zammad logs, restrict or remove internet exposure, rotate credentials on and around the host, and segment the helpdesk server. Because the beachhead was a session rather than a credential, session security and logging deserve a specific review.
Top comments (0)