AI description
CVE-2026-102490 is a local privilege escalation vulnerability affecting Zammad, an open-source helpdesk and ticketing system. The flaw is present in all versions of the software, including the latest alpha releases, and allows a local user with access to the `zammad` account to bypass permission checks and escalate their privileges to `root`. This unauthorized access enables the execution of privileged operations, allowing an attacker to modify system files, install software, or access other parts of the host system. The vulnerability was highlighted in reports after being chained with CVE-2026-102489 in an attack against the Dutch Institute for Vulnerability Disclosure (DIVD). In that incident, attackers utilized an autonomous, agentic AI to exploit both flaws, allowing them to hijack sessions, execute code remotely, and escalate privileges to root within seconds. Following evidence of active exploitation in the wild, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-102490 to its Known Exploited Vulnerabilities (KEV) catalog, requiring organizations to apply the necessary updates.
- Description
- All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
- Source
- csirt@divd.nl
- NVD status
- Analyzed
- Products
- zammad
CVSS 4.0
- Type
- Secondary
- Base score
- 9.4
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Zammad GmbH Zammad Improper Privilege Management Vulnerability
- Exploit added on
- Oct 2, 2026
- Exploit action due
- Oct 5, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-269
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
7
🚨 CISA KEV — ZAMMAD CVE-2026-102489 + CVE-2026-102490 (SESSION FIXATION → RCE + LPE TO ROOT) CISA added two Zammad vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog on October 2, 2026, based on evidence of active exploitation. • Product: Zammad (help
@DailyDarkWeb
2 Oct 2026
3275 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-102490: Zammad Privilege Escalation to Root Actively Exploited — Detec… "On October 2, 2026, CISA added CVE-2026-102490 to the Known Exploited…" 🔗 https://t.co/U5Ye8yCy9X #CyberSecurity #ThreatIntel #cve2026102490 #critical #cisakev
@SecurityAr58409
2 Oct 2026
24 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔴 Actively exploited: CISA confirms active exploitation of two critical Zammad flaws that lead to root access CVE-2026-102489 · CVE-2026-102490 CVE-2026-102489 and CVE-2026-102490, both rated CVSS 9.4, were added to CISA's KEV… #CVE #Zammad #infosec https://t.co/G8Ppqz4oI
@Orbitaley
2 Oct 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
csirt_it: ‼️ #Exploited #Zammad: rilevato sfruttamento attivo in rete delle vulnerabilità CVE-2026-102489 e CVE-2026-102490 Rischio: 🔴 Tipologia: 🔸 Remote Code Execution 🔸 Privilege Escalation 🔗 https://t.co/LVuz6tZqkT ⚠️ Importante mantenere agg… https
@Vulcanux_
2 Oct 2026
25 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
‼️ #Exploited #Zammad: rilevato sfruttamento attivo in rete delle vulnerabilità CVE-2026-102489 e CVE-2026-102490 Rischio: 🔴 Tipologia: 🔸 Remote Code Execution 🔸 Privilege Escalation 🔗 https://t.co/1tnc0Toes6 ⚠️ Importante mantenere aggiornati i sistemi h
@csirt_it
2 Oct 2026
282 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
News: DIVD was breached by an AI-led attack chaining Zammad zero-days CVE-2026-102489 and CVE-2026-102490. Sessions hijacked, root gained, data stolen. Upgrade to Zammad 7 or take it offline; check IoCs. https://t.co/qwThwq9asX
@snakeyesV1
2 Oct 2026
98 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers exploited Zammad zero-day flaws CVE-2026-102489 and CVE-2026-102490 to gain root at DIVD. Upgrade to Zammad 7 or go offline. #Zammad #ZeroDay #CVE2026102489 #CVE2026102490 #DIVD #AIAgent #ExploitedInTheWild https://t.co/A9KXk55U07
@Daily_CyberSec
2 Oct 2026
218 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
DIVD: AI 에이전트가 Zammad 제로데이로 침해(9/21). CVE-2026-102489 세션 하이재킹→RCE, CVE-2026-102490 로컬→root. 연쇄로 수 초 만에 권한 상승. 자원봉사자 이메일 등 유출 조사 중. Zammad 7 업그레이드 또는 오프라인 권고.
@none_gram
2 Oct 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
DIVD got hacked through AI agents that chained two Zammad zero-days: session hijack→RCE (CVE-2026-102489) and local root (CVE-2026-102490). Casefile published Sept 30. If you run Zammad, upgrade to 7 — or take it offline. https://t.co/Pxl88sJsXc
@justelite
1 Oct 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F35B8C68-B265-4574-BEF5-51FC1CB4DF77",
"versionEndExcluding": "7.1.0",
"versionStartIncluding": "1.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:zammad:zammad:7.1.0:alpha:*:*:*:*:*:*",
"matchCriteriaId": "4DD0F01F-638A-4E1E-A53A-F38EF44D196B",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:docker:docker:-:*:*:*:*:*:*:*",
"matchCriteriaId": "231A8A55-A319-4878-91DA-4FD91CF0549E",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*",
"matchCriteriaId": "703AF700-7A70-47E2-BC3A-7FD03B3CA9C1",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
]