All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
⚠️ Actively exploited — CISA KEV
This CVE was added to CISA's Known Exploited Vulnerabilities catalog on 2026-10-02. It is confirmed exploited in the wild and must be patched as a priority.
Remediation deadline (US federal agencies): 2026-10-05
CVSS v3.1 Score
9.8
/ 10.0
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Information
- Published
- 30 sept. 2026
- Updated
- 7 oct. 2026
- Status
- Analyzed
- Source
- csirt@divd.nl
Affected products
zammad zammad
Versions : 7.1.0
Weaknesses (CWE)
CWE-269
References (5)
- https://csirt.divd.nl/CVE-2026-102490Third Party Advisory
- https://csirt.divd.nl/DIVD-2026-00015Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-102490US Government Resource
Similar CVEs
Other vulnerabilities of type CWE-269
Loading…
Monitor your products
Get automatic alerts for every new CVE affecting your equipment.