Zammad helpdesk CVE-2026-102489/102490 (DIVD/Merlon via Bleeping 30 Sep): zero-day chain → session hijack, RCE, root — upgrade to 7.x
BleepingComputer (30 September 2026), citing the Dutch Institute for Vulnerability Disclosure (DIVD) and Merlon Security, reports that DIVD’s agentic-AI network breach used a chain of two previously undisclosed Zammad open-source helpdesk/ticketing zero-days now tracked as CVE-2026-102489 and CVE-2026-102490. Used together they enabled session hijacking, remote code execution, and privilege escalation from the Zammad user to root in seconds with AI automation; attackers then accessed other services and exfiltrated data. Network segmentation and IR limited deeper movement; DIVD investigation ongoing. DIVD is notifying other vulnerable Zammad operators and recommends upgrading to Zammad version 7 (considered safe) or taking instances offline ASAP; further DIVD public detail expected. Zammad markets self-hosted and hosted helpdesk (vendor cites 2,000+ customers / 55,000+ users). As of this desk pass: NVD detail pages for these CVE IDs were not yet populated; GitHub zammad/zammad security advisory list did not yet surface matching GHSA entries — wire-primary until Zammad/DIVD publish a full advisory. No public CVSS on sources used. Distinct from desk divd-ai-agent-breach-20260924 (incident card; this is the product patch path). Primary wire: BleepingComputer 30 Sep; co-discoverers: DIVD + Merlon.
- Product
- Zammad open-source helpdesk / ticketing (self-hosted and hosted)
- Versions
- Vulnerable builds exploited at DIVD not fully enumerated publicly; DIVD/Bleeping: upgrade to Zammad 7.x (safe) or take instance offline. Prefer vendor GHSA/release once published.
- Exploited in Australia?
- unknown
- Patch to
- Upgrade Zammad to version 7.x immediately (DIVD recommendation) or take the instance offline until patched. Hunt for unexpected session reuse, Zammad-user → root escalation, and rapid automated post-exploit. Watch Zammad GitHub security advisories / release notes and DIVD victim notices for exact fixed builds and IoCs. No CVSS invented — await NVD/vendor.
Primary: BleepingComputer — DIVD: Zammad zero-days enabled AI-driven breach (30 Sep 2026) · Vendor: Zammad Security Advisories archive (watch for matching GHSA / release notes) · CVE: CVE-2026-102489, CVE-2026-102490 · DIVD CSIRT — It was a matter of when, not if… (24 Sep 2026; incident primary)
