What happened
CISA added both CVEs to the KEV catalog on 2026-10-02 with confirmed exploitation. CVE-2026-102489 is a session-fixation flaw (CWE-384) that can chain to remote code execution as the zammad service user; CVE-2026-102490 is an improper privilege-management flaw (CWE-269) letting the local zammad user escalate to root. Zammad's own advisory explicitly states CVE-2026-102490 'is reported as being actively exploited.' Federal due date 2026-10-05 under BOD 26-04.
Why it matters
Zammad is a widely self-hosted customer-support platform whose AI-agent and AI-ticket functionality runs on the same application and host. The confirmed in-the-wild RCE-to-root chain means a compromised Zammad instance gives an attacker full control of the host that runs the org's AI support agents — including the model credentials, prompt/filter configurations, and any connected ticketing/AI backend.
Attack vector
Remote session fixation to gain an authenticated session, then chain to RCE as the zammad user; a separate local escalation path from the zammad user to root.
Affected systems
Zammad (session-fixation vulnerability can be chained with CVE-2026-102490 to RCE as the zammad user; local privilege escalation to root)
Mitigation
Apply Zammad's patched releases per https://zammad.com/en/product/releases/ before the 2026-10-05 federal deadline; treat as actively exploited — review for prior compromise and rotate credentials on the affected host.