CVE-2026-102490 Details
Description
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
A local privilege escalation vulnerability has been identified in Zammad, affecting all versions from 1.5.0 up to 7.1.0-alpha. This vulnerability allows a local Zammad user to escalate privileges to root.
Users are advised to upgrade to Zammad version 7.1.0 or later. For those seeking to verify if they have been compromised, a verification script is available to check Zammad log files for indicators of compromise.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://csirt.divd.nl/CVE-2026-102490 | [email protected] | AdvisoryBundle |
| https://csirt.divd.nl/DIVD-2026-00015 | [email protected] | BundleTechnical Description |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Zammad GmbH Zammad | >= 1.5.0, < 7.1.0-alpha (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion