CVE-2026-102490

CRITICAL CISA KEV Pub 30/09 Upd 03/10

Overview

The vulnerability is a privilege escalation flaw rooted in improper permission handling within Zammad's local user management. Specifically, the local 'zammad' user account is able to escalate privileges to root due to insufficient access control enforcement in the underlying privilege separation mechanism. This affects all versions of the Zammad application, including the latest alpha releases, impacting the system's user privilege boundary.

Vulnerability Description

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

Impact

An attacker with access to the local 'zammad' user account can escalate privileges to root, gaining full administrative control over the affected system. This enables execution of arbitrary commands with root privileges, potentially leading to complete system compromise, data exposure, or disruption of services. The exploit requires only a low-privileged local account, which may be obtained through other means or insider access, significantly increasing the risk of lateral movement and full system takeover within the environment.

Solution

Users should apply the security updates provided by Zammad GmbH as detailed in the DIVD advisory DIVD-2026-00015. The vendor recommends upgrading to patched versions that correct the privilege escalation flaw, including all stable releases beyond 7.1.0 alpha. Detailed patch instructions and version-specific fixes are available at https://csirt.divd.nl/DIVD-2026-00015. No alternative workarounds are specified; prompt application of the vendor's updates is advised to mitigate this issue.

EPSS vs KEV Prediction — Evolution (30 days)

Affected Products (2)

Vendor Product Version CPE
zammad Zammad Zammad All cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*
zammad Zammad Zammad 7.1.0 cpe:2.3:a:zammad:zammad:7.1.0:alpha:*:*:*:*:*:*

Exploits

No exploits found for this CVE.

Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest VERY HIGH
Sightings Extensive activity

Threat Feed

6 events
2026-10-03
Threat Sensor Sighting — Extensive activity

Sighting activity recorded

2026-10-02
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-10-02
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

2026-10-01
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-09-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

Detected as Exploited in the Wild (383 sightings)

Active exploitation confirmed with 383 sighting(s)

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.

Attack Vectors ML

Privilege Escalation
98% privilege_escalation
Insecure Direct Object Reference
52% idor
Authentication Bypass
48% auth_bypass

MITRE ATT&CK Techniques (0)

ATT&CK techniques pending

Techniques are derived from this CVE's kill chains once ML classification completes.

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-122 Privilege Abuse
30%
High Medium
CAPEC-233 Privilege Escalation
30%
— —
CAPEC-58 Restful Privilege Elevation
30%
High High

Red Team Playbook

AtomicRedTeam integration in progress

Executable commands will be auto-mapped to each ATT&CK technique of this CVE.

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (4)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2026-102490
csirt.divd.nl
GitHub CVE third-party-advisory
https://csirt.divd.nl/DIVD-2026-00015
csirt.divd.nl
GitHub CVE third-party-advisory
https://csirt.divd.nl/CVE-2026-102490
cisa.gov
NVD API US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-102490