Cyber & AI intelligence
Wasteland.
Briefs indexed2982
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-102490 2026-10-02

Zammad Local Privilege Escalation (CVE-2026-102490) Actively Exploited, CISA Adds to KEV

"CISA added CVE-2026-102490 to its Known Exploited Vulnerabilities (KEV) catalog on 2026-10-02. The flaw lets the local `zammad` user escalate to root, and it is being exploited in the wild."

CISA added CVE-2026-102490 to its Known Exploited Vulnerabilities (KEV) catalog on 2026-10-02. The flaw lets the local zammad user escalate to root, and it is being exploited in the wild.

What Is It

CVE-2026-102490 is an improper privilege management vulnerability (CWE-269) in Zammad, the help desk platform from Zammad GmbH. According to NVD, "all versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root." CISA notes that the flaw can be chained with CVE-2026-102489. The supplied sources give no further detail on that companion CVE.

DIVD CSIRT reported the vulnerability. NVD published it on 2026-09-30, and its analysis status is "Analyzed."

Why It Matters

CISA's KEV listing confirms active exploitation. CISA's SSVC assessment also records exploitation as "active" with "total" technical impact. The CVSS v4.0 vector from DIVD marks exploit maturity as "Attacked."

Severity scores: - CVSS 3.1 (NVD): 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) - CVSS 4.0 (DIVD): 9.4 Critical

Both vectors are scored as network-reachable with no privileges required. That differs from the written description, which talks about a local user escalating privileges. The likely explanation is that the scores reflect the chained attack with CVE-2026-102489, but the sources do not say so.

CISA has flagged this entry for forensic triage. Whether it has been used in ransomware campaigns is listed as "Unknown."

What's Vulnerable

Patch Status

The supplied data names no fixed version. NVD's description says all versions are affected, including the latest alpha.

CISA's required action is to apply mitigations according to the vendor's instructions. Agencies must follow BOD 26-04 and CISA's Forensics Triage Requirements. If mitigations are not available, they must follow BOD 26-04 guidance for cloud services or stop using the product. Stakeholders must also assess each asset's internet exposure.

Federal due date: 2026-10-05.

Check Zammad's release notes and community advisory for mitigation guidance.

Sources