important · Research
Two exploited Zammad flaws take an unauthenticated helpdesk caller to root.
Affects
Zammad, a self-hosted customer-support and ticketing platform commonly deployed on Linux.
The chain begins with unauthenticated Internet reachability to an affected self-hosted Zammad instance.
Detail and 4 sources
Session hijacking reaches code execution as the zammad service user, and a second flaw elevates that user to root.
DIVD reproduced both stages and observed the complete chain during its own compromise.
The available remediation is partial, leaving one stage of the observed root chain unresolved.