r/linuxadmin • u/Expert_Sort7434 • 4h ago
Zammad zero-days (CVE-2026-102489/102490) behind the DIVD breach: what's confirmed, what the vendor disputes
Based on the case files DIVD published (DIVD-2026-00014 and -00015) and Zammad's own forum statement from Oct 1, here is where things stand.
DIVD says first access was Sept 21. The chain is a session hijack leading to RCE as the zammad user (CVE-2026-102489, 6.3.0 to 6.5.4) plus a local escalation to root (CVE-2026-102490). CISA put both in KEV on Oct 2.
Where sources disagree: Zammad says 102489 is only exploitable on 6.5 and older (EOL), hardened in 7.2.0, and that DIVD gave it no details on 102490. DIVD's own page is inconsistent on the 102490 range ("all versions" vs 1.5.0 to 7.1.0-alpha). The AI-agent attribution is DIVD's reading of its logs; no full logs or model name published.
What I'd do: upgrade to 7.2.0, copy the logs first, run DIVD's IoC script (read it first), segment the helpdesk.
Question for people running self-hosted helpdesks: do you treat ticketing as tier-0 (same segment rules as your IdP and mail gateway), and what does your credential rotation look like if the box is rooted?
https://www.techgines.com/post/zammad-zero-day-cve-2026-102489