## Overview
CISA added CVE-2026-102490 to its Known Exploited Vulnerabilities (KEV) catalog on October 2, 2026. This vulnerability affects all versions of Zammad, including the latest alpha. It allows local users to escalate their privileges to root. The addition to the KEV list indicates a federal deadline for remediation, suggesting active exploitation in the wild.
## Technical Details
CVE-2026-102490 is classified as an improper privilege management vulnerability. It enables a local zammad user to gain root access. This flaw can be chained with CVE-2026-102489, amplifying its impact. The specific conditions under which the escalation occurs have not been publicly detailed, but the potential for abuse is significant given the high CVSS score of 9.4.
## Impact
The ability for local users to escalate privileges to root poses a severe risk to systems running Zammad. An attacker with root access can control the entire system, leading to data breaches, unauthorized access to sensitive information, and potential system downtime. Organizations using Zammad should assess their exposure and implement immediate countermeasures.
## Mitigation
Defenders should prioritize patching affected Zammad installations. Zammad GmbH is expected to release a security update addressing this vulnerability. Until a patch is applied, limit access to the local zammad user account and monitor for any suspicious activity. Implementing strict access controls and user permissions can help mitigate the risk of exploitation.
CSURFACE Threat Sensor