Zammad CVE-2026-102489 and CVE-2026-102490 chain yields root
Zammad is affected by a two-stage exploit chain: CVE-2026-102489 turns a hijacked session into remote code execution as the zammad user, and CVE-2026-102490 escalates that to root. The chain is rated 9.4 Critical on CVSS 4.0, both flaws are exploited in the wild, and root is reached in seconds.
- CVE-2026-102489: no privileges, score 8.7, RCE as zammad
- CVE-2026-102490: local escalation to root, score 8.5
- Affected: Zammad 6.3.0–6.5.4 and 1.5.0–7.1.0 alpha
- ZoomEye found 11,977 Zammad instances online
Read next
Security