Build1 publisher2 min readPublished
Chained Zammad CVEs took DIVD from hijacked session to root in seconds
DIVD said attackers chained two Zammad zero-days on its own internet-facing server and went from a hijacked session to root in seconds. It assessed that an AI agent was involved and says upgrading to version 7 is not a complete fix for both flaws.
The Engineer · Build desk

What happened
- DIVD reported that after gaining root the attackers read data from the compromised environment and exfiltrated it.
- The organisation said network segmentation and its incident response kept the attackers from moving deeper into its systems and network.
- DIVD published an indicator-of-compromise script in its case file so operators can scan their own Zammad logs for the same intrusion.
- The within-seconds figure covers only the hijack, the code execution and the escalation to root, and DIVD did not disclose how long the full run including data theft took.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision DIVD does not say the privilege-escalation flaw is patched in version 7, so the safe move is to confirm the fixed version with the vendor or keep Zammad offline, not to assume the upgrade closed it.
- exposure DIVD will not say whether the first flaw needs prior authentication, so anyone exposing a Zammad login in the vulnerable range cannot rule out an unauthenticated route to the same session-and-code-execution foothold.
- constraint The hijack-to-root chain ran in seconds, faster than manual response can act, so DIVD's countermeasures are telemetry stored off the box and containment automated to the same timescale.
Upgrading to version 7 does less than the word suggests, and DIVD says so directly. It lists Zammad 6.3.0 through 6.5.4 as exploitable and says 7.0.0 through 7.1.3 still contain CVE-2026-102489; what blocks the attack in version 7 is the environment, not a code change [5]. An environmental block is not a patch. Alter the deployment and the flaw is in reach again. DIVD's advice to anyone self-hosting is to upgrade to version 7 or take the instance offline [18].
The chain is two moves. CVE-2026-102489 hands an attacker a hijacked session and code execution as the zammad user, the unprivileged account the application runs under, and DIVD could not reconstruct from the public material which of those two came first [7]. CVE-2026-102490 then lifts that zammad user to root, and the escalation needs exactly the local access the first flaw provides [8][17]. From root, the attackers reached other services on the host [8].
Detailed attack requests have not been published [6]. The version you upgrade to also tells you nothing about whether you were already breached; a version number cannot answer that. DIVD noted that users might see abnormal ticketing behaviour, but said no specific user-visible symptoms have been disclosed [19]. It titled its account "When hackers get hacked, we deal with it in hacker style," and published it on September 30 with a case file update the next day [15][14].
What to watch
- Vendor confirmation of whether, and in which version, CVE-2026-102490 is actually patched.
- Release of the attack requests or the authentication requirement for CVE-2026-102489, which would settle the exposure question.
- Independent corroboration of DIVD's assessment that an AI agent drove the chain.