← Vulnerability feed

Vulnerability record · CVE-2026-102490 · published 30 September 2026

CVE-2026-102490: Zammad improper privilege management vulnerability

Zammad · Zammad

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

9.4 CVSS 4.0 Critical CISA KEV since 2 Oct 2026 EPSS 0.63% · top 51.7% CWE-269 · Improper privilege management
9.4CVSS 4.0 base score
0.63%EPSS exploitation probability, 30 days
YesIn CISA KEV, federal fix due in 0 days
1Affected product versions listed by NVD
3References
3 Oct 2026Last modified by NVD

Description

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:

Exploitation in the wild

CISA added CVE-2026-102490 to the Known Exploited Vulnerabilities catalog on 2 October 2026 as "Zammad GmbH Zammad Improper Privilege Management Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 5 October 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-102490 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2026-102489Zammad vulnerabilityZammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerabilit…KEVEPSS 0.58%9.8CVE-2022-48021Zammad vulnerabilityA vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server.EPSS 0.88%9.8CVE-2022-35490Zammad improper restriction of authentication attempts vulnerabilityZammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a co…EPSS 0.89%9.8CVE-2021-42090Zammad deserialization of untrusted data vulnerabilityAn issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.EPSS 2.3%9.8CVE-2021-42094Zammad command injection vulnerabilityAn issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.EPSS 1.9%9.8CVE-2020-26030Zammad improper authentication vulnerabilityAn issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configure…EPSS 1.4%9.8CVE-2017-6080Zammad cross-site request forgery vulnerabilityAn issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protection mechanism involving HTTP A…EPSS 0.73%9.8CVE-2017-5619Zammad improper authentication vulnerabilityAn issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g.…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2026-102490), CISA KEV, FIRST EPSS (scores of 2026-10-03). This page is refreshed as NVD updates the record.