CVE-2026-102490

Published Sep 30, 2026

Last updated 4 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-102490 is a local privilege escalation vulnerability affecting Zammad, an open-source helpdesk and ticketing system. The flaw is present in all versions of the software, including the latest alpha releases, and allows a local user with access to the `zammad` account to bypass permission checks and escalate their privileges to `root`. This unauthorized access enables the execution of privileged operations, allowing an attacker to modify system files, install software, or access other parts of the host system. The vulnerability was highlighted in reports after being chained with CVE-2026-102489 in an attack against the Dutch Institute for Vulnerability Disclosure (DIVD). In that incident, attackers utilized an autonomous, agentic AI to exploit both flaws, allowing them to hijack sessions, execute code remotely, and escalate privileges to root within seconds. Following evidence of active exploitation in the wild, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-102490 to its Known Exploited Vulnerabilities (KEV) catalog, requiring organizations to apply the necessary updates.

Description
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
Source
csirt@divd.nl
NVD status
Analyzed
Products
zammad

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.4
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Zammad GmbH Zammad Improper Privilege Management Vulnerability
Exploit added on
Oct 2, 2026
Exploit action due
Oct 5, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-269

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

7

  1. 🚨 CISA KEV — ZAMMAD CVE-2026-102489 + CVE-2026-102490 (SESSION FIXATION → RCE + LPE TO ROOT) CISA added two Zammad vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog on October 2, 2026, based on evidence of active exploitation. • Product: Zammad (help

    @DailyDarkWeb

    2 Oct 2026

    3275 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🔒 #CyberSecurity CVE-2026-102490: Zammad Privilege Escalation to Root Actively Exploited — Detec… "On October 2, 2026, CISA added CVE-2026-102490 to the Known Exploited…" 🔗 https://t.co/U5Ye8yCy9X #CyberSecurity #ThreatIntel #cve2026102490 #critical #cisakev

    @SecurityAr58409

    2 Oct 2026

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🔴 Actively exploited: CISA confirms active exploitation of two critical Zammad flaws that lead to root access CVE-2026-102489 · CVE-2026-102490 CVE-2026-102489 and CVE-2026-102490, both rated CVSS 9.4, were added to CISA's KEV… #CVE #Zammad #infosec https://t.co/G8Ppqz4oI

    @Orbitaley

    2 Oct 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. csirt_it: ‼️ #Exploited #Zammad: rilevato sfruttamento attivo in rete delle vulnerabilità CVE-2026-102489 e CVE-2026-102490 Rischio: 🔴 Tipologia: 🔸 Remote Code Execution 🔸 Privilege Escalation 🔗 https://t.co/LVuz6tZqkT ⚠️ Importante mantenere agg… https

    @Vulcanux_

    2 Oct 2026

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. ‼️ #Exploited #Zammad: rilevato sfruttamento attivo in rete delle vulnerabilità CVE-2026-102489 e CVE-2026-102490 Rischio: 🔴 Tipologia: 🔸 Remote Code Execution 🔸 Privilege Escalation 🔗 https://t.co/1tnc0Toes6 ⚠️ Importante mantenere aggiornati i sistemi h

    @csirt_it

    2 Oct 2026

    282 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. News: DIVD was breached by an AI-led attack chaining Zammad zero-days CVE-2026-102489 and CVE-2026-102490. Sessions hijacked, root gained, data stolen. Upgrade to Zammad 7 or take it offline; check IoCs. https://t.co/qwThwq9asX

    @snakeyesV1

    2 Oct 2026

    98 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Attackers exploited Zammad zero-day flaws CVE-2026-102489 and CVE-2026-102490 to gain root at DIVD. Upgrade to Zammad 7 or go offline. #Zammad #ZeroDay #CVE2026102489 #CVE2026102490 #DIVD #AIAgent #ExploitedInTheWild https://t.co/A9KXk55U07

    @Daily_CyberSec

    2 Oct 2026

    218 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. DIVD: AI 에이전트가 Zammad 제로데이로 침해(9/21). CVE-2026-102489 세션 하이재킹→RCE, CVE-2026-102490 로컬→root. 연쇄로 수 초 만에 권한 상승. 자원봉사자 이메일 등 유출 조사 중. Zammad 7 업그레이드 또는 오프라인 권고.

    @none_gram

    2 Oct 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. DIVD got hacked through AI agents that chained two Zammad zero-days: session hijack→RCE (CVE-2026-102489) and local root (CVE-2026-102490). Casefile published Sept 30. If you run Zammad, upgrade to 7 — or take it offline. https://t.co/Pxl88sJsXc

    @justelite

    1 Oct 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations