Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Session Fixation & Privilege‑Escalation Flaws in Zammad Helpdesk Platform (CVE‑2026‑102489 / CVE‑2026‑102490)

CISA added two CVE‑2026‑1024xx vulnerabilities in the open‑source Zammad ticketing system to its KEV catalog. The flaws enable session hijacking and root‑level privilege escalation, forcing organizations to patch immediately and prove control‑assurance for audit readiness.

LiveThreat™ Intelligence · 📅 October 03, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
securityaffairs.com

Critical Session Fixation & Privilege‑Escalation Flaws in Zammad Helpdesk Platform (CVE‑2026‑102489 / CVE‑2026‑102490)

What It Is – Two high‑severity vulnerabilities were disclosed in the open‑source ticketing system Zammad. CVE‑2026‑102489 is a session‑fixation flaw that lets an attacker hijack a user’s session and execute code as the zammad user. CVE‑2026‑102490 is an improper‑privilege‑management bug that enables the same zammad user to obtain root privileges.

Exploitability – Both CVEs have a CVSS 9.4 score and are listed in the U.S. CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active, real‑world exploitation. A proof‑of‑concept chain has been demonstrated, allowing an attacker to move from a compromised session to full system control in seconds.

Affected Products – Zammad versions 6.3.0‑6.5.4 and 7.0.0‑7.1.3 are vulnerable to CVE‑2026‑102489; versions 1.5.0‑7.1.0‑alpha are vulnerable to CVE‑2026‑102490.

Why It Matters for Trust & Control Assurance

  • Access‑control hygiene – Session fixation and unchecked privilege escalation break the core control objective of “secure authentication and least‑privilege enforcement.”
  • Audit‑ready evidence – Demonstrating that you have patched or mitigated these flaws provides concrete evidence for auditors and satisfies multiple framework requirements (e.g., NIST CSF Identify/Protect, ISO 27001 Access Control).
  • Continuous monitoring – Detecting anomalous session creation or unexpected privilege changes is a key signal in a real‑time control‑monitoring program that enterprises now expect from vendors.

Recommended Actions

  • Upgrade all Zammad deployments to version 7.0 or later (or temporarily take the service offline).
  • Verify that session tokens are regenerated after authentication and that privilege‑escalation paths are hardened.
  • Enable logging of session‑creation events and privilege‑change events; feed these logs into a SIEM for continuous monitoring.
  • Conduct a rapid control‑gap assessment against the “access‑control” objective and capture remediation evidence for audit purposes.

Source: Security Affairs – CISA adds Zammad flaws to KEV catalog

📰 Original Source
https://securityaffairs.com/200248/security/u-s-cisa-adds-zammad-gmbh-zammad-flaws-to-its-known-exploited-vulnerabilities-catalog.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →