Summary
- DIVD says CVE-2026-102489 was abused during its 21 September breach.
- CVE-2026-102490 can allow the local Zammad user to escalate privileges to root.
- DIVD recommends upgrading to Zammad 7 and says its investigation remains open.
A compromise of the Dutch Institute for Vulnerability Disclosure has led to the disclosure of two Zammad vulnerabilities that can move an attacker from application-level access towards root privileges on an affected system.
DIVD said the flaws were identified while investigating its own 21 September breach. CVE-2026-102489 affects Zammad 6.3.0 through 6.5.4 and can provide remote code execution in the context of a Zammad user, including the possibility of session leakage.
The vulnerability is also present in Zammad 7.0.0 through 7.1.3, although DIVD says environmental conditions prevent exploitation in those versions.
A second flaw, CVE-2026-102490, can allow the local Zammad user to escalate privileges to root. DIVD lists affected versions from 1.5.0 through the 7.1.0 alpha release.
The organisation recommends upgrading to Zammad 7 or taking affected instances offline. Patches are listed as available, while DIVD continues scanning and notifying owners of vulnerable systems.
The sequence is unusual because DIVD is itself a vulnerability-disclosure organisation whose work depends on externally accessible systems for handling reports, cases, and communications. Its investigation moved rapidly from victim response into vulnerability research and coordinated notification of other potentially affected organisations.
DIVD’s timeline says malicious access occurred on 21 September. The vulnerabilities were analysed and reproduced over the following two days and reported to Zammad on 24 September, with scanning and owner notifications beginning shortly afterwards.
That sequence compresses several functions that normally sit with different organisations: incident response, vulnerability research, vendor disclosure, internet-wide exposure assessment, and victim notification. It also illustrates how incident response and vulnerability disclosure can converge where an attacker reaches a product through a previously unknown weakness.
The privilege-escalation flaw changes the potential consequence of the application-level compromise. Code execution in a service context can already expose application data and sessions, while escalation to root can place the wider host, configuration, credentials, logs, and adjacent services at risk depending on the deployment.
DIVD has separately described its breach as involving AI agents. That remains the organisation’s assessment of an active investigation rather than an independently established account of the attacker’s automation or tooling. The more firmly supported technical finding is that the two Zammad vulnerabilities exist and that DIVD says one was abused in its breach.
The distinction is increasingly important as incidents acquire an AI label before the underlying mechanics are fully understood. Automation can change the speed and sequencing of an intrusion, but the outcome still depends on concrete weaknesses — here, application code execution and local privilege escalation — that can be analysed separately from the attacker’s orchestration layer.
Zammad installations can also contain information that is particularly useful after compromise, including support conversations, internal infrastructure references, customer information, authentication details, and administrative workflows. A ticketing platform may not normally be treated as part of the security stack, but the information it aggregates can make it operationally sensitive.
DIVD’s case remains open. Its current recommendation is to move to Zammad 7, while notification of vulnerable instances and investigation of the original breach continue.





