Critical Session Fixation & Privilege‑Escalation Flaws in Zammad Helpdesk Platform (CVE‑2026‑102489 / CVE‑2026‑102490)
What It Is – Two high‑severity vulnerabilities were disclosed in the open‑source ticketing system Zammad. CVE‑2026‑102489 is a session‑fixation flaw that lets an attacker hijack a user’s session and execute code as the zammad user. CVE‑2026‑102490 is an improper‑privilege‑management bug that enables the same zammad user to obtain root privileges.
Exploitability – Both CVEs have a CVSS 9.4 score and are listed in the U.S. CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active, real‑world exploitation. A proof‑of‑concept chain has been demonstrated, allowing an attacker to move from a compromised session to full system control in seconds.
Affected Products – Zammad versions 6.3.0‑6.5.4 and 7.0.0‑7.1.3 are vulnerable to CVE‑2026‑102489; versions 1.5.0‑7.1.0‑alpha are vulnerable to CVE‑2026‑102490.
Why It Matters for Trust & Control Assurance
- Access‑control hygiene – Session fixation and unchecked privilege escalation break the core control objective of “secure authentication and least‑privilege enforcement.”
- Audit‑ready evidence – Demonstrating that you have patched or mitigated these flaws provides concrete evidence for auditors and satisfies multiple framework requirements (e.g., NIST CSF Identify/Protect, ISO 27001 Access Control).
- Continuous monitoring – Detecting anomalous session creation or unexpected privilege changes is a key signal in a real‑time control‑monitoring program that enterprises now expect from vendors.
Recommended Actions
- Upgrade all Zammad deployments to version 7.0 or later (or temporarily take the service offline).
- Verify that session tokens are regenerated after authentication and that privilege‑escalation paths are hardened.
- Enable logging of session‑creation events and privilege‑change events; feed these logs into a SIEM for continuous monitoring.
- Conduct a rapid control‑gap assessment against the “access‑control” objective and capture remediation evidence for audit purposes.
Source: Security Affairs – CISA adds Zammad flaws to KEV catalog