Skip to finding
important · Research

Two exploited Zammad flaws take an unauthenticated helpdesk caller to root.

Affects

Zammad, a self-hosted customer-support and ticketing platform commonly deployed on Linux.

The chain begins with unauthenticated Internet reachability to an affected self-hosted Zammad instance.

Detail and 4 sources

Session hijacking reaches code execution as the zammad service user, and a second flaw elevates that user to root.

DIVD reproduced both stages and observed the complete chain during its own compromise.

The available remediation is partial, leaving one stage of the observed root chain unresolved.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, October 3, 2026