Vulnerability  ·  2026-10-03

KEV: Zammad session-fixation-to-RCE chain + local root privilege escalation, actively exploited (CVE-2026-102489/102490)

VulnerabilityHigh impactGlobalCVE-2026-102489
CISA added both CVEs to the KEV catalog on 2026-10-02 with confirmed exploitation. CVE-2026-102489 is a session-fixation flaw (CWE-384) that can chain to remote code execution as the zammad service user; CVE-2026-102490 is an improper privilege-management flaw (CWE-269) letting the local zammad user escalate to root. Zammad's own advisory explicitly states CVE-2026-102490 'is reported as being actively exploited.' Federal due date 2026-10-05 under BOD 26-04.
Zammad is a widely self-hosted customer-support platform whose AI-agent and AI-ticket functionality runs on the same application and host. The confirmed in-the-wild RCE-to-root chain means a compromised Zammad instance gives an attacker full control of the host that runs the org's AI support agents — including the model credentials, prompt/filter configurations, and any connected ticketing/AI backend.
Remote session fixation to gain an authenticated session, then chain to RCE as the zammad user; a separate local escalation path from the zammad user to root.
Zammad (session-fixation vulnerability can be chained with CVE-2026-102490 to RCE as the zammad user; local privilege escalation to root)
Apply Zammad's patched releases per https://zammad.com/en/product/releases/ before the 2026-10-05 federal deadline; treat as actively exploited — review for prior compromise and rotate credentials on the affected host.
CISA KEV catalogZammad community advisoryZammad releases
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →