we_are_coded.by CODE · The world, decoded
БГ
Zammad

Zammad publicly disputes how DIVD disclosed two flaws, and CISA listed both in KEV with a 5 October deadline

CISA · event date: 2 October 2026Security

CVE-2026-102489 and CVE-2026-102490 in the Zammad ticketing system can be chained: from code execution to root. Per DIVD's timeline, Zammad was notified on 24 September. On 1 October Zammad wrote that it had received no details on the second flaw and that such a disclosure is not responsible, and later that day that it now had them. CISA is not waiting for the argument.

In short
  • On 2 October CISA listed CVE-2026-102489 (session fixation, code as the zammad user) and CVE-2026-102490 (up to root). They can be chained. Deadline 5 October.
  • DIVD: Zammad was notified on 24 September, scanning for vulnerable instances and a limited disclosure on 26 September. Zammad: this is not a responsible way.
  • Both sides: from 7.0 up, the first flaw is not exploitable in practice. Zammad recommends 7.2.0 and says 6.5 and older should be updated immediately.
Checked on5 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

One side writes that it reported on 24 September. The other, that by 1 October it had seen no technical details of the second flaw. In the middle is CISA, which listed both with three days to fix.

The facts: on 2 October 2026 CISA added two Zammad vulnerabilities to the KEV catalog: CVE-2026-102489, session fixation (CWE-384), which can lead to remote code execution as the zammad user, and CVE-2026-102490, improper privilege management (CWE-269), where the local zammad user can escalate to root. CISA says the two can be chained. Federal deadline 5 October 2026, forensic triage required, ransomware use unknown. The Dutch Institute for Vulnerability Disclosure (DIVD) describes them in case DIVD-2026-00015: per its timeline, the flaw was used to breach DIVD itself on 21 September, Zammad was notified on 24 September, and on 26 September DIVD scanned for vulnerable instances, made a limited disclosure and began notifying owners. For the first flaw DIVD gives affected versions 6.3.0 to 6.5.4 and 7.0.0 to 7.1.3, and on 7.0.0 to 7.1.3 it is not exploitable in practice; the second, in its words, affects all versions from 1.5.0 to 7.1.0-alpha. Zammad writes in its community on 1 October that for CVE-2026-102489 it received a report in August 2026, that exploitation is possible only on 6.5 and older, which are out of support, that 7.0 and later are not affected, and that the code is hardened in 7.2.0. For CVE-2026-102490 Zammad writes that DIVD gave it no technical details, that it cannot verify a claim it has not seen, and that a disclosure in which a CVE identifier was published for a flaw it had not been told about is not a responsible way to do it. A later post in the same thread: Zammad has received the details from DIVD and is working on them; the flaw cannot be exploited remotely on its own, an attacker would already need access to the server. Zammad recommends 7.2.0, and anyone on 6.5 or older should update immediately.

They agree on one thing: on 7.0 and up the first flaw is not exploitable in practice. They differ on sequence. One side has already scanned and disclosed, the other, at the time of its statement, had not yet seen what exactly is in the second.

The dispute is about the order of disclosure. Your server is not part of it.

A KEV listing is CISA's claim that the flaws are being exploited, and the deadline is its action. There is one practical point in Zammad's own words: 6.5 and older no longer receive security fixes, because their support has ended.

The recommendation is 7.2.0. On 6.5 or older, you update today. Then see who has access to the server, because by Zammad's account the second flaw needs an attacker who is already inside.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CISA - Known Exploited Vulnerabilities Catalog, CVE-2026-102489 and CVE-2026-102490, 02.10.2026→Zammad - Zammad statement on vulnerability reports in DIVD case DIVD-2026-00015, Zammad community, 01.10.2026→DIVD CSIRT - DIVD-2026-00015, Vulnerabilities in Zammad
Original: https://wearecoded.com/en/articles/zammad-cve-2026-102490-spor-s-divd.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news