ZeroDayAlert

CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability

Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.

Zammad GmbH Zammad Added to KEV 2026-10-02 Federal due 2026-10-05 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Zammad GmbH Zammad installations are affected by an improper privilege management vulnerability that allows the local zammad user to escalate privileges to root. The vulnerability is most serious in environments where the zammad service runs with elevated permissions or where local access to the zammad account is possible. The record does not specify which versions of Zammad are affected or whether cloud-hosted deployments are similarly vulnerable.

How to check whether this touches you

  • Confirm whether Zammad is deployed in your environment by searching your asset inventory and service discovery records for "Zammad" or related ticketing system instances.
  • Establish whether the zammad system user exists on the affected hosts and whether it is used to run the Zammad service.
  • Document the current version of Zammad running in each instance; check the admin interface or package manager (dpkg -l | grep zammad on Debian/Ubuntu, or rpm -qa | grep zammad on Red Hat systems). Version numbers alone are not proof of patch status, as backported fixes may be deployed by your distribution.
  • Identify whether local shell access to the zammad user account is restricted or whether unprivileged users can obtain such access.

What to do

  1. Contact Zammad GmbH immediately and request vendor-issued mitigation or patch guidance specific to your version and deployment model (self-hosted or cloud).
  2. If a patch is available, schedule its deployment within the timeframe specified by CISA BOD 26-04 based on your asset's internet exposure and criticality classification.
  3. Pending patching, restrict local shell access to the zammad user account to only trusted administrators; disable login for that account if the service does not require interactive shell access.
  4. If mitigations are unavailable and the system is internet-facing or handles sensitive data, escalate to your information security team for evaluation of whether continued operation is acceptable.
  5. Enable and retain audit logs (auditd on Linux, or equivalent) to capture any privilege escalation attempts or suspicious activity by the zammad user; configure centralized logging if available.

If you find you were exposed

Privilege escalation vulnerabilities are often exploited after initial compromise; search your audit logs and authentication logs for unexpected privilege escalation events or root access granted to the zammad user within the period between the vulnerability's public disclosure and your patching date. Examine system logs for evidence of lateral movement or persistence mechanisms installed after privilege escalation. If your log retention period is shorter than the time between vulnerability disclosure and patch deployment, document this gap and ensure longer retention is configured for future incidents.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-102490 is being exploited. It cannot tell you whether Zammad is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →