CVE-2026-102490
published 2026-09-30CVE-2026-102490: All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
PriorityP185critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-10-05
Exploited in the wild
EPSS
0.63%
48.4th percentile
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zammad | zammad | — | — |
| zammad | zammad | >= 1.5.0 < 7.1.0 | 7.1.0 |
| zammad_gmbh | zammad | >= 1.5.0 < 7.1.0-alpha | 7.1.0-alpha |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.4CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:X
vulncheck9.4CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Zammad GmbH Zammad Improper Privilege Management Vulnerability
cisa·2026-10-02·CVSS 9.8
CVE-2026-102490 [CRITICAL] CWE-269 Zammad GmbH Zammad Improper Privilege Management Vulnerability
Vulnerability: Zammad GmbH Zammad Improper Privilege Management Vulnerability
Affected: Zammad GmbH Zammad
Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patchi
CISA
Zammad GmbH Zammad Session Fixation Vulnerability
cisa·2026-10-02·CVSS 9.8
CVE-2026-102489 [CRITICAL] CWE-384 Zammad GmbH Zammad Session Fixation Vulnerability
Vulnerability: Zammad GmbH Zammad Session Fixation Vulnerability
Affected: Zammad GmbH Zammad
Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Notes: https://zammad
GHSA
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
ghsa_unreviewed·2026-09-30
CVE-2026-102490 [CRITICAL] All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
VulnCheck
zammad zammad Vulnerability
vulncheck·2026·CVSS 9.4
CVE-2026-102490 [CRITICAL] zammad zammad Vulnerability
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
Affected: zammad zammad
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://csirt.divd.nl/cases/DIVD-2026-00015/; https://www.linkedin.com/posts/zammad-share-7511092586393010176-RkCb/
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
blogs_hackernews·2026-10-05·CVSS 7.5
CVE-2026-88779 [HIGH] ⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook.
There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. Some attacks are getting more capable. Others are still getting in because the basics gave way first.
Here’s what mattered this week.
## ⚡ Threat of the Week
Citrix Warns of Ne
Hackernews
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
blogs_hackernews·2026-10-01
CVE-2025-4632 ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years.
That is the lesson running through the list. Attackers do not always need a brilliant new trick. They can hide commands in public infrastructure, reuse old flaws, abuse weak defaults, or let automation stitch together a rough path that still w
2026-09-30
Published
2026-10-02
Added to CISA KEV
Exploited in the wild