CVE-2026-102490: Zammad GmbH Zammad
Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.
- Vendor
- Zammad GmbH
- Product
- Zammad
- Vulnerability
- Zammad GmbH Zammad Improper Privilege Management Vulnerability
- Date added
- Oct 2, 2026
- CISA due date (U.S. federal agencies)
- Oct 5, 2026
- Known ransomware campaign use
- Unknown
- Weakness (CWE)
- CWE-269
References
This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.
Last updated: · Catalog version 2026.10.02