<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Zammad - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/zammad/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 09 Oct 2026 12:52:50 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/zammad/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Local Privilege Escalation Vulnerability in Zammad</title><link>https://feed.craftedsignal.io/briefs/2026-10-zammad-privilege-escalation/</link><pubDate>Fri, 09 Oct 2026 12:52:50 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-zammad-privilege-escalation/</guid><description>A local attacker can exploit a vulnerability in Zammad to perform privilege escalation on the host system.</description><content:encoded><![CDATA[<p>The BSI (German Federal Office for Information Security) has identified a vulnerability in Zammad that allows a local attacker to escalate their privileges. The vulnerability is contingent upon the attacker already possessing local access to the server hosting the Zammad instance. By leveraging this flaw, a local user can bypass standard security controls to achieve higher-level system permissions. This represents a risk to organizations that have not restricted local system access or that rely on Zammad as a service with shared-user environments. Defenders should ensure that the principle of least privilege is applied to all system users and that Zammad service accounts are hardened against local lateral movement and escalation attempts.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a local user to obtain elevated privileges on the host operating system. This could lead to full system compromise, unauthorized access to sensitive helpdesk data, or the ability to manipulate the Zammad application and its underlying data stores.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Ensure Zammad is updated to the latest available version provided by the vendor to address security defects.</li>
<li>Apply the principle of least privilege for all local system accounts with access to the Zammad server.</li>
<li>Restrict local shell access to the server solely to authorized administrators to mitigate the risk of local privilege escalation.</li>
<li>Audit existing local user accounts and groups on the server to ensure no unauthorized persistence or escalation vectors exist.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>privilege-escalation</category><category>vulnerability</category><category>local-access</category></item><item><title>Active Exploitation of Zammad Remote Code Execution and Privilege Escalation Vulnerabilities</title><link>https://feed.craftedsignal.io/briefs/2026-09-zammad-zero-days/</link><pubDate>Wed, 30 Sep 2026 19:45:40 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-zammad-zero-days/</guid><description>Zammad helpdesk software is being actively exploited via two zero-day vulnerabilities, including an unauthenticated RCE (CVE-2026-102489) and an unpatched privilege escalation flaw (CVE-2026-102490).</description><content:encoded><![CDATA[<p>Since September 21, 2026, threat actors have been actively exploiting two zero-day vulnerabilities within Zammad, a widely used helpdesk and customer support software. The first vulnerability, CVE-2026-102489, is a critical remote code execution (RCE) flaw that allows unauthenticated attackers to execute arbitrary code on the underlying server. This issue affects Zammad versions 6.3.0 through 6.5.4 and has been addressed with a security update.</p>
<p>The second vulnerability, CVE-2026-102490, allows an attacker with limited access to elevate their privileges to root, granting full system control. This vulnerability currently affects all current versions of Zammad and remains unpatched as of September 30, 2026. Given the active exploitation observed in the wild, organizations running Zammad are at high risk of complete system compromise, data theft, and persistent unauthorized access. Defenders must prioritize patching the RCE vulnerability and monitoring for unauthorized privilege escalation attempts.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs reconnaissance to identify public-facing instances of Zammad.</li>
<li>Attacker sends specially crafted, unauthenticated HTTP requests to exploit CVE-2026-102489.</li>
<li>The target Zammad server processes the malicious request, resulting in remote code execution (RCE) with the privileges of the web service account.</li>
<li>Attacker executes post-exploitation commands to download additional tooling or establish persistence.</li>
<li>Attacker leverages the limited-privilege shell to exploit CVE-2026-102490.</li>
<li>The vulnerability in Zammad allows the attacker to escalate to root privileges.</li>
<li>Attacker gains full system control, facilitating data exfiltration, modification, or further lateral movement within the network.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities allows for unauthenticated remote code execution and full root privilege escalation on Zammad instances. This provides attackers with complete control over customer support data, communication logs, and internal credentials stored within the application. Given the nature of helpdesk platforms, compromised systems may serve as a significant pivot point for broader organizational network intrusion. Active exploitation has been confirmed since September 21, 2026, posing a critical risk to all sectors utilizing Zammad.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Apply the security update provided by Zammad for CVE-2026-102489 immediately across all instances of versions 6.3.0 through 6.5.4.</li>
<li>For CVE-2026-102490, since no patch is currently available, increase monitoring of administrative account logins and unauthorized process execution originating from the Zammad application user.</li>
<li>Before applying updates, export and secure application and network logs as recommended by the NCSC to facilitate forensic analysis should evidence of exploitation be discovered.</li>
<li>Coordinate with IT-service providers to verify the current version of Zammad installations and assess exposure risk.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>vulnerability</category><category>rce</category><category>privilege-escalation</category><category>webserver</category></item></channel></rss>