CISA adds Zammad GmbH CVE-2026-102489 to the Known Exploited Vulnerabilities catalog, due 2026-10-05

A session-fixation flaw that the catalog says can yield remote code execution as the zammad user is now on the known-exploited list, paired with a same-day root-escalation record and a three-day remediation clock.

IN BRIEF: On 2026-10-02 the Cybersecurity and Infrastructure Security Agency added CVE-2026-102489, the Zammad GmbH Zammad Session Fixation Vulnerability, to catalog version 2026.10.02 of the Known Exploited Vulnerabilities feed, with a due date of 2026-10-05.

RECORD:
Date: 2026-10-02
Beat: Known Exploited Vulnerabilities
Jurisdiction: United States
Entity: Zammad GmbH (product: Zammad)
Instrument / cite: CVE-2026-102489
Source type: CISA Catalog of Known Exploited Vulnerabilities JSON feed
Confidence: confirmed
Record ID: N/A

Source: CISA

The Cybersecurity and Infrastructure Security Agency placed CVE-2026-102489 on the CISA Catalog of Known Exploited Vulnerabilities on 2026-10-02. Catalog version 2026.10.02, released at 2026-10-02T15:19:38.2945Z, contains 1,733 entries. The new record names the vendor Zammad GmbH, the product Zammad, and the vulnerability “Zammad GmbH Zammad Session Fixation Vulnerability.” Date added and the catalog release date are the same day.

The catalog’s short description is the operative finding. “Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.” CISA lists the weakness as CWE-384. The consequence recorded is not a generic integrity loss. It is remote code execution running as the zammad user. The entry does not publish affected version ranges, a CVSS score, or exploit detail.

The same feed carries the record the description points to. CVE-2026-102490 is titled “Zammad GmbH Zammad Improper Privilege Management Vulnerability,” weakness CWE-269, also added on 2026-10-02. Its short description states: “Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.” Each entry names the other. Read as the catalog wrote them, the path is session fixation to code execution as the zammad user, then improper privilege management from that local user to root. Closing one record and leaving the other open does not close the chain the feed describes.

Both entries share a due date of 2026-10-05. From the date added, that is three days. knownRansomwareCampaignUse is “Unknown” on each. The catalog records known exploitation without attributing a ransomware campaign. forensicTriage is “Yes” on both, and the required action sends stakeholders to CISA’s “Forensics Triage Requirements.”

The required action is identical. “Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset’s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.” Two controls sit in that sentence beyond a routine patch: forensic triage, and discontinuation where mitigations are unavailable. Internet exposure is assigned to the stakeholder to evaluate. The feed does not assert that every Zammad instance is exposed.

The notes field does not embed a fixed version. It points to the vendor releases page at https://zammad.com/en/product/releases/, to https://nvd.nist.gov/vuln/detail/CVE-2026-102489, to BOD 26-04 at https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk, and to the forensics implementation guidance at https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk. It also links a Zammad community thread whose URL path states that CVE-2026-102490 “is reported as being actively exploited.” That wording is in the link CISA published in notes. It is not a ransomware attribution. The catalog’s own ransomware field remains Unknown.

For an enterprise buyer, the listing changes the question from whether a session flaw has been discussed to whether the asset can meet a 2026-10-05 due date under BOD 26-04 Prioritizing Security Updates Based on Risk. The discontinue-use clause is the residual instruction if vendor mitigations cannot be applied in time. Cloud deployments are not exempt in the action language. They are told to follow applicable BOD 26-04 guidance for cloud services.

A founder whose product embeds Zammad, or whose delivery team runs it as the system that holds customer correspondence, inherits the buyer’s clock. The catalog does not name customers, agencies, or an incident. What it does name is the execution identity: the zammad user first, root only through the chained CVE-2026-102490 record. An estate that treats the application user as a contained account has to reconcile that assumption with a CWE-269 entry added the same day, same due date, same triage flag.

Investor scrutiny follows the same split. The feed supports a claim of known exploitation and a claim of a chain to root. It does not support a claim of ransomware use, a count of exposed hosts, or a named campaign. Confidence is highest on the catalog facts themselves: vendor, product, CVE identifiers, weakness classes, dates, triage flag, and the required action. Confidence is lower on anything the notes only link, including the community thread’s report of active exploitation of the privilege-escalation CVE.

Federal and other stakeholders covered by the action language have a narrower window than a standard maintenance cycle. 2026-10-05 is the date in both records. The catalog version that carries them is 2026.10.02, inside a feed of 1,733 known-exploited vulnerabilities. The addition is a completed catalog act, not a proposed rule.

WHY IT MATTERS: Listing CVE-2026-102489 puts a session-fixation path to code execution as the zammad user on a known-exploited clock that ends 2026-10-05, and the same feed says that user can be chained through CVE-2026-102490 to root. Buyers and operators who cannot apply vendor mitigations inside that window are told to discontinue use, and to triage, not merely to patch.

[ncr_subscribe]
Subscribe
Notify of
0 Comments
Oldest
Newest Most Voted
0
Would love your thoughts, please comment.x
()
x