CVE-2026-102490
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
- Published Sep 30, 2026
- CVSS 9.4 critical
- 0.6% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
Affected software
In the news
- ⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests The Hacker News ·
- CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA ·
- ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories The Hacker News ·
- AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit Help Net Security ·
- Zammad Zero-Days Exploited in AI-Powered DIVD Hack SecurityWeek ·
- DIVD says Zammad zero-days enabled AI-driven network breach BleepingComputer ·