CVE-2026-102490

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

0.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 3 mentions (2026-09-30); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-09-30: 3Mentions · 2026-10-01: 109-3010-01
Referenced assets5 URLs
Full discourse4 posts
  • Aviatrix Threat Research Center@aviatrixtrc

    An autonomous AI agent exploited two Zammad zero-days (CVE-2026-102489, CVE-2026-102490) to breach DIVD in seconds. The AI escalated from user to root and moved laterally without human intervention. Network segmentation helped contain the AI's autonomous lateral movement. #ZeroDay #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/divd-zammad-zero-days-ai-driven-network-breach-2026

    0000049
    2.0K followersView on X
  • Cybermerge@cybermergemedia

    Sources: DIVD case page (timeline, affected versions, log check script): https://csirt.divd.nl/DIVD-2026-00015 NCSC-NL alert, Sep 30: https://www.ncsc.nl/alerts/actief-misbruik-van-zeroday-kwetsbaarheden-in-zammad-update-nu https://CVE.org: CVE-2026-102489, CVE-2026-102490 (DIVD is the CNA)

    0000036
    40 followersView on X
  • Cybermerge@cybermergemedia

    Per http://CVE.org (DIVD CNA): CVE-2026-102489 is session hijack to RCE as the zammad user, CVE-2026-102490 takes that user to root. DIVD says an AI agent chained them in seconds and segmentation kept it contained. Zammad 7 blocks the RCE, but NCSC says the root bug is unpatched.

    0000046
    40 followersView on X
  • SecureChap@SecureChap

    Zammad versions before 7.x let attackers hijack sessions straight into RCE and root. Two flaws, tracked as CVE-2026-102489 and CVE-2026-102490, allowed session fixation followed by unauthenticated command execution. DIVD and Merlon Security found the chain during routine testing. An attacker used the same path to breach the DIVD network. Segmentation kept the blast radius small once the initial foothold was gained. Check your Zammad install against the latest 7.x release and apply the session-handling patches now.

    0000043
    172 followersView on X

Explore more