CISA added CVE-2026-102490 to its Known Exploited Vulnerabilities (KEV) catalog on 2026-10-02. The flaw lets the local zammad user escalate to root, and it is being exploited in the wild.
What Is It
CVE-2026-102490 is an improper privilege management vulnerability (CWE-269) in Zammad, the help desk platform from Zammad GmbH. According to NVD, "all versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root." CISA notes that the flaw can be chained with CVE-2026-102489. The supplied sources give no further detail on that companion CVE.
DIVD CSIRT reported the vulnerability. NVD published it on 2026-09-30, and its analysis status is "Analyzed."
Why It Matters
CISA's KEV listing confirms active exploitation. CISA's SSVC assessment also records exploitation as "active" with "total" technical impact. The CVSS v4.0 vector from DIVD marks exploit maturity as "Attacked."
Severity scores:
- CVSS 3.1 (NVD): 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- CVSS 4.0 (DIVD): 9.4 Critical
Both vectors are scored as network-reachable with no privileges required. That differs from the written description, which talks about a local user escalating privileges. The likely explanation is that the scores reflect the chained attack with CVE-2026-102489, but the sources do not say so.
CISA has flagged this entry for forensic triage. Whether it has been used in ransomware campaigns is listed as "Unknown."
What's Vulnerable
- Product: Zammad (Zammad GmbH)
- Platforms: Linux and Docker deployments
- Affected versions (CNA): 1.5.0 up to, but not including, 7.1.0-alpha
- NVD CPE match: 1.5.0 up to, but not including, 7.1.0, plus 7.1.0-alpha explicitly
- Versions before 1.5.0: status listed as "unknown"
Patch Status
The supplied data names no fixed version. NVD's description says all versions are affected, including the latest alpha.
CISA's required action is to apply mitigations according to the vendor's instructions. Agencies must follow BOD 26-04 and CISA's Forensics Triage Requirements. If mitigations are not available, they must follow BOD 26-04 guidance for cloud services or stop using the product. Stakeholders must also assess each asset's internet exposure.
Federal due date: 2026-10-05.
Check Zammad's release notes and community advisory for mitigation guidance.
Sources
- CISA KEV Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-102490
- NVD, CVE-2026-102490: https://nvd.nist.gov/vuln/detail/CVE-2026-102490
- DIVD CSIRT, CVE-2026-102490: https://csirt.divd.nl/CVE-2026-102490
- DIVD CSIRT, DIVD-2026-00015: https://csirt.divd.nl/DIVD-2026-00015
- Zammad Releases: https://zammad.com/en/product/releases/
- Zammad Community advisory: https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297/2
- CISA BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance (Forensics Triage Requirements): https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk