CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability

Summary

Zammad GmbH Zammad has an improper privilege management vulnerability allowing local users to escalate privileges to root. This flaw can be chained with CVE-2026-102489, and CISA mandates mitigations by October 5, 2026, aligning with BOD 26-04.

IFF Assessment

FOE

This vulnerability allows for privilege escalation, which is a significant security weakness that attackers can exploit to gain unauthorized control.

Severity

7.8 High (AI Estimated)

This is an estimated CVSS score for improper privilege management, which typically involves an attack vector allowing local access and a high impact on confidentiality, integrity, and availability. The chaining with another CVE suggests potential for increased exploitability and impact.

CISA KEV: Listed as actively exploited. Federal patch due: October 05, 2026. Known ransomware use: Unknown.

Defender Context

Defenders need to be aware of this privilege escalation vulnerability in Zammad. Prompt application of vendor-provided mitigations is crucial, especially for systems exposed to the internet, to prevent unauthorized access and potential lateral movement by attackers.

Read Full Story →