Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3919 articles · 228580 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-102490PATCHED
zammad · zammad

Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha

Description

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

Affected Products

VendorProductVersions
zammadzammad1.5.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
dockerdockercve_cpe95%
linuxlinux_kernelcve_cpe95%
zammadzammadcert_advisory90%

References

  • https://csirt.divd.nl/DIVD-2026-00015(third-party-advisory)
  • https://csirt.divd.nl/CVE-2026-102490(third-party-advisory)
  • https://zammad.com/en/advisories/cve-2026-102489-cve-2026-102490(vendor-advisory)
  • https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297/2(technical-description)

Related News (8 articles)

Tier D
Heise Security2d ago
Warnung vor Angriffen auf Zammad und Citrix NetScaler
→ No new info (linked only)
Tier D
The Hacker News6d ago
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
→ No new info (linked only)
Tier E
Hacker News6d ago
Did an AI Agent Hack DIVD? The Zammad Zero-Days
→ No new info (linked only)
Tier D
Help Net Security6d ago
AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit
→ No new info (linked only)
Tier B
BSI Advisories6d ago
[NEU] [kritisch] Zammad: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode und Privilegieneskalation
→ No new info (linked only)
Tier D
SecurityWeek6d ago
Zammad Zero-Days Exploited in AI-Powered DIVD Hack
→ No new info (linked only)
Tier D
BleepingComputer6d ago
DIVD says Zammad zero-days enabled AI-driven network breach
→ No new info (linked only)
Tier C
VulDB7d ago
CVE-2026-102490 | Zammad privileges management
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV❌ No
Actively exploited❌ No
Patch available
7.1.0-alpha
PublishedSep 30, 2026
Trending Score49
Source articles8
Independent8
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-102489
Undisclosed RCE in Zammad v6.3 and higher
Trending: 87
NONECVE-2026-56725
Zammad: Denial of Service via OTRS Import Controller
Trending: 8
NONECVE-2026-84458
Zammad: Account takeover via unverified email matching during SSO auto-link
Trending: 8
NONECVE-2026-61525
Zammad: Arbitrary File Deletion via Unvalidated Session Identifier in Long Polling Controller
Trending: 8
NONECVE-2026-56732
Zammad: Malicious input in Ticket Body Enables Session Termination
Trending: 7

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 30, 2026
Discovered by ZDM
Sep 30, 2026
Patch Available
Oct 7, 2026