OCTOBER 2, 2026
Live Feed
Back to database
Case File

CVE-2026-102490

CRITICAL · CVSS 9.8 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-02

CyberRota Analysis

AI-Generated

All versions of Zammad, including the latest alpha release, are vulnerable to a local privilege escalation flaw that allows a user with zammad access to gain root privileges. This critical vulnerability poses significant risks to system integrity and confidentiality, making it imperative for organizations using Zammad to prioritize immediate remediation. System administrators and security teams should act swiftly to mitigate potential exploitation.

CVE
CVE-2026-102490
Severity
CRITICAL
CVSS
9.8
EPSS
0.26%

Original NVD Description

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

Related CVEs

Other vulnerabilities affecting the same vendor(s)