{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/zammad/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Zammad"],"_cs_severities":["medium"],"_cs_tags":["privilege-escalation","vulnerability","local-access"],"_cs_type":"advisory","_cs_vendors":["Zammad"],"content_html":"\u003cp\u003eThe BSI (German Federal Office for Information Security) has identified a vulnerability in Zammad that allows a local attacker to escalate their privileges. The vulnerability is contingent upon the attacker already possessing local access to the server hosting the Zammad instance. By leveraging this flaw, a local user can bypass standard security controls to achieve higher-level system permissions. This represents a risk to organizations that have not restricted local system access or that rely on Zammad as a service with shared-user environments. Defenders should ensure that the principle of least privilege is applied to all system users and that Zammad service accounts are hardened against local lateral movement and escalation attempts.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a local user to obtain elevated privileges on the host operating system. This could lead to full system compromise, unauthorized access to sensitive helpdesk data, or the ability to manipulate the Zammad application and its underlying data stores.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnsure Zammad is updated to the latest available version provided by the vendor to address security defects.\u003c/li\u003e\n\u003cli\u003eApply the principle of least privilege for all local system accounts with access to the Zammad server.\u003c/li\u003e\n\u003cli\u003eRestrict local shell access to the server solely to authorized administrators to mitigate the risk of local privilege escalation.\u003c/li\u003e\n\u003cli\u003eAudit existing local user accounts and groups on the server to ensure no unauthorized persistence or escalation vectors exist.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T12:52:50Z","date_published":"2026-10-09T12:52:50Z","id":"https://feed.craftedsignal.io/briefs/2026-10-zammad-privilege-escalation/","summary":"A local attacker can exploit a vulnerability in Zammad to perform privilege escalation on the host system.","title":"Local Privilege Escalation Vulnerability in Zammad","url":"https://feed.craftedsignal.io/briefs/2026-10-zammad-privilege-escalation/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-102490"},{"id":"CVE-2026-102489"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Zammad (6.3.0 - 6.5.4)","Zammad (all current versions)","Zammad"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","privilege-escalation","webserver"],"_cs_type":"threat","_cs_vendors":["Zammad"],"content_html":"\u003cp\u003eSince September 21, 2026, threat actors have been actively exploiting two zero-day vulnerabilities within Zammad, a widely used helpdesk and customer support software. The first vulnerability, CVE-2026-102489, is a critical remote code execution (RCE) flaw that allows unauthenticated attackers to execute arbitrary code on the underlying server. This issue affects Zammad versions 6.3.0 through 6.5.4 and has been addressed with a security update.\u003c/p\u003e\n\u003cp\u003eThe second vulnerability, CVE-2026-102490, allows an attacker with limited access to elevate their privileges to root, granting full system control. This vulnerability currently affects all current versions of Zammad and remains unpatched as of September 30, 2026. Given the active exploitation observed in the wild, organizations running Zammad are at high risk of complete system compromise, data theft, and persistent unauthorized access. Defenders must prioritize patching the RCE vulnerability and monitoring for unauthorized privilege escalation attempts.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify public-facing instances of Zammad.\u003c/li\u003e\n\u003cli\u003eAttacker sends specially crafted, unauthenticated HTTP requests to exploit CVE-2026-102489.\u003c/li\u003e\n\u003cli\u003eThe target Zammad server processes the malicious request, resulting in remote code execution (RCE) with the privileges of the web service account.\u003c/li\u003e\n\u003cli\u003eAttacker executes post-exploitation commands to download additional tooling or establish persistence.\u003c/li\u003e\n\u003cli\u003eAttacker leverages the limited-privilege shell to exploit CVE-2026-102490.\u003c/li\u003e\n\u003cli\u003eThe vulnerability in Zammad allows the attacker to escalate to root privileges.\u003c/li\u003e\n\u003cli\u003eAttacker gains full system control, facilitating data exfiltration, modification, or further lateral movement within the network.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows for unauthenticated remote code execution and full root privilege escalation on Zammad instances. This provides attackers with complete control over customer support data, communication logs, and internal credentials stored within the application. Given the nature of helpdesk platforms, compromised systems may serve as a significant pivot point for broader organizational network intrusion. Active exploitation has been confirmed since September 21, 2026, posing a critical risk to all sectors utilizing Zammad.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the security update provided by Zammad for CVE-2026-102489 immediately across all instances of versions 6.3.0 through 6.5.4.\u003c/li\u003e\n\u003cli\u003eFor CVE-2026-102490, since no patch is currently available, increase monitoring of administrative account logins and unauthorized process execution originating from the Zammad application user.\u003c/li\u003e\n\u003cli\u003eBefore applying updates, export and secure application and network logs as recommended by the NCSC to facilitate forensic analysis should evidence of exploitation be discovered.\u003c/li\u003e\n\u003cli\u003eCoordinate with IT-service providers to verify the current version of Zammad installations and assess exposure risk.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T14:14:25Z","date_published":"2026-09-30T19:45:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-zammad-zero-days/","summary":"Zammad helpdesk software is being actively exploited via two zero-day vulnerabilities, including an unauthenticated RCE (CVE-2026-102489) and an unpatched privilege escalation flaw (CVE-2026-102490).","title":"Active Exploitation of Zammad Remote Code Execution and Privilege Escalation Vulnerabilities","url":"https://feed.craftedsignal.io/briefs/2026-09-zammad-zero-days/"}],"language":"en","title":"CraftedSignal Threat Feed - Zammad","version":"https://jsonfeed.org/version/1.1"}