CVE-2026-102490
Zammad local privilege escalation to root affects versions before 7.1.0-alpha (CVE-2026-102490)
Zammad versions 1.5.0 to before 7.1.0-alpha allow the local zammad user to escalate privileges to root. CISA KEV lists the flaw as exploited; its due date is 5 October 2026. The listed fixed version is 7.1.0-alpha, and no vendor workaround is published.
What happened
The CVE record describes a local privilege escalation in Zammad. An attacker who already holds the local zammad account on the server can use that access to obtain root. The vulnerability is rated critical with a CVSS 4.0 score of 9.4.
CISA's KEV entry lists CVE-2026-102490 as exploited. It was added on 2 October 2026 and carries a due date of 5 October 2026. No vendor advisory or vendor-written mitigation is listed in the CVE record; the accompanying references are from DIVD.
The supporting SSVC assessment rates technical impact as total and automatable as no.
Who is affected
Zammad versions 1.5.0 through before 7.1.0-alpha are affected. The CVE record names only the product and that version range; it does not describe particular deployment sizes or roles. Treat every Zammad installation in the organisation — production, staging, test, and container images — as in scope until you can confirm the running version. If you use Zammad through a managed hosting or SaaS arrangement, confirm with the provider that the underlying host is not running an affected version.
What to do now
- Identify all Zammad installations running versions 1.5.0 through before 7.1.0-alpha.
- Upgrade to the listed fixed version, Zammad 7.1.0-alpha. No earlier fixed release is listed.
- No vendor workaround has been published. If you cannot upgrade or otherwise mitigate, follow CISA's KEV required action and discontinue use of the product if mitigations are unavailable.
- Review affected hosts for signs that the zammad account has already obtained root, and follow CISA's BOD 26-04 prioritisation and forensics triage requirements referenced in the KEV entry.
How to detect it
Monitor authentication and privilege-change logs on Zammad hosts for the local zammad account gaining root. Pay particular attention to sudo, su, and session transitions outside planned maintenance. No vendor-supplied indicators of compromise have been published.
Beyond the patch
Because CISA KEV records exploitation, detection and response should be the immediate priority after patching. Spirity's Managed Detection & Response (MDR) can monitor affected hosts for post-exploitation activity, and an Incident Response Retainer gives you a named team for containment if a Zammad host has already been compromised.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Zammad | 1.5.0 – < 7.1.0-alpha | 7.1.0-alpha |