Skip to content

CVE-2026-102490

Zammad local privilege escalation to root affects versions before 7.1.0-alpha (CVE-2026-102490)

Critical 9.4 KEV Published

Zammad versions 1.5.0 to before 7.1.0-alpha allow the local zammad user to escalate privileges to root. CISA KEV lists the flaw as exploited; its due date is 5 October 2026. The listed fixed version is 7.1.0-alpha, and no vendor workaround is published.

What happened

The CVE record describes a local privilege escalation in Zammad. An attacker who already holds the local zammad account on the server can use that access to obtain root. The vulnerability is rated critical with a CVSS 4.0 score of 9.4.

CISA's KEV entry lists CVE-2026-102490 as exploited. It was added on 2 October 2026 and carries a due date of 5 October 2026. No vendor advisory or vendor-written mitigation is listed in the CVE record; the accompanying references are from DIVD.

The supporting SSVC assessment rates technical impact as total and automatable as no.

Who is affected

Zammad versions 1.5.0 through before 7.1.0-alpha are affected. The CVE record names only the product and that version range; it does not describe particular deployment sizes or roles. Treat every Zammad installation in the organisation — production, staging, test, and container images — as in scope until you can confirm the running version. If you use Zammad through a managed hosting or SaaS arrangement, confirm with the provider that the underlying host is not running an affected version.

What to do now

  1. Identify all Zammad installations running versions 1.5.0 through before 7.1.0-alpha.
  2. Upgrade to the listed fixed version, Zammad 7.1.0-alpha. No earlier fixed release is listed.
  3. No vendor workaround has been published. If you cannot upgrade or otherwise mitigate, follow CISA's KEV required action and discontinue use of the product if mitigations are unavailable.
  4. Review affected hosts for signs that the zammad account has already obtained root, and follow CISA's BOD 26-04 prioritisation and forensics triage requirements referenced in the KEV entry.

How to detect it

Monitor authentication and privilege-change logs on Zammad hosts for the local zammad account gaining root. Pay particular attention to sudo, su, and session transitions outside planned maintenance. No vendor-supplied indicators of compromise have been published.

Beyond the patch

Because CISA KEV records exploitation, detection and response should be the immediate priority after patching. Spirity's Managed Detection & Response (MDR) can monitor affected hosts for post-exploitation activity, and an Incident Response Retainer gives you a named team for containment if a Zammad host has already been compromised.

Affected and fixed versions

ProductAffectedFixed in
Zammad1.5.0 – < 7.1.0-alpha7.1.0-alpha

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.