CVE-2026-102490
Overview
The vulnerability is a privilege escalation flaw rooted in improper permission handling within Zammad's local user management. Specifically, the local 'zammad' user account is able to escalate privileges to root due to insufficient access control enforcement in the underlying privilege separation mechanism. This affects all versions of the Zammad application, including the latest alpha releases, impacting the system's user privilege boundary.
Vulnerability Description
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
Impact
An attacker with access to the local 'zammad' user account can escalate privileges to root, gaining full administrative control over the affected system. This enables execution of arbitrary commands with root privileges, potentially leading to complete system compromise, data exposure, or disruption of services. The exploit requires only a low-privileged local account, which may be obtained through other means or insider access, significantly increasing the risk of lateral movement and full system takeover within the environment.
Solution
Users should apply the security updates provided by Zammad GmbH as detailed in the DIVD advisory DIVD-2026-00015. The vendor recommends upgrading to patched versions that correct the privilege escalation flaw, including all stable releases beyond 7.1.0 alpha. Detailed patch instructions and version-specific fixes are available at https://csirt.divd.nl/DIVD-2026-00015. No alternative workarounds are specified; prompt application of the vendor's updates is advised to mitigate this issue.
EPSS vs KEV Prediction — Evolution (30 days)
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Zammad | Zammad | All |
cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*
|
|
|
Zammad | Zammad | 7.1.0 |
cpe:2.3:a:zammad:zammad:7.1.0:alpha:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
6 eventsSighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Sighting activity recorded
Sighting activity recorded
Active exploitation confirmed with 383 sighting(s)
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.
Attack Vectors ML
MITRE ATT&CK Techniques (0)
Techniques are derived from this CVE's kill chains once ML classification completes.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-122 | Privilege Abuse |
30%
|
High | Medium | |
| CAPEC-233 | Privilege Escalation |
30%
|
— | — | |
| CAPEC-58 | Restful Privilege Elevation |
30%
|
High | High |
Red Team Playbook
Executable commands will be auto-mapped to each ATT&CK technique of this CVE.
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2026-102490 |
| csirt.divd.nl |
GitHub CVE
third-party-advisory
|
https://csirt.divd.nl/DIVD-2026-00015 |
| csirt.divd.nl |
GitHub CVE
third-party-advisory
|
https://csirt.divd.nl/CVE-2026-102490 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-102490 |