Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-10-01 · updated: 2026-10-01 · tags: [cve, privilege-escalation, zammad, active-exploitation] · confidence: high · severity: critical · affected_sectors: [global, technology] · au_impact: false

All versions of Zammad, including the latest alpha, allow the local zammad user to escalate privileges to root. DIVD found it with Merlon Security and disclosed it on 30 September 2026 as the second half of the chain used against DIVD's own network: paired with a session-hijacking and remote code execution flaw, it took the attacker from a hijacked Zammad session to root in seconds under agentic control, after which other services were reached and data was exfiltrated. Network segmentation and incident response contained the intrusion before deeper movement; DIVD recommends upgrading to Zammad version 7 or taking instances offline.

Attribute Detail
CVE CVE-2026-102490
CVSS 9.4 (Critical) — CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Vendor / product Zammad — open-source helpdesk and ticketing platform
Reported 2026-09-30