Zammad Security Update on DIVD Case DIVD-2026-00015 (CVE-2026-102489 / CVE-2026-102490)

Dear community,

We know that reports like these can be concerning, especially if you are running and maintaining your own Zammad instance. We therefore wanted to share our current assessment as clearly as possible and give you the most important information at a glance.

TL;DR:

  • Zammad 7.0 and later are not affected by CVE-2026-102489 in practice.
  • CVE-2026-102490 is a local privilege escalation issue and cannot be exploited remotely on its own.
  • We recommend updating to Zammad 7.2.0 and restricting server access to trusted administrators.

You can find the full advisory here:
:backhand_index_pointing_right: Security Advisory: CVE-2026-102489 & CVE-2026-102490 | Zammad

And as always: thank you to everyone in the community who helps us keep Zammad secure by reporting issues, asking questions, and sharing information responsibly.