CVE Vulnerabilities

CVE-2026-102490

Improper Privilege Management

Published: Sep 30, 2026 | Modified: Oct 02, 2026
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
ZammadZammad1.5.0 (including)7.1.0 (excluding)
ZammadZammad7.1.0-alpha (including)7.1.0-alpha (including)

Potential Mitigations

References