← Back to CVE List
Vulnerability Intelligence Report
Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha

CVE-2026-102490

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
8.5
HIGH
EPSS Probability:0.26%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-269 ↗CWE-269 Improper Privilege Management

Affected Products & Versions

Vendor Product Affected Versions
Zammad GmbH Zammad 1.5.0 < 7.1.0-alpha (affected), * < 1.5.0 (unknown)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
0.262%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityDutch Institute for Vulnerability Disclosure (DIVD) · Researcher · Netherlands
Reserved2026-09-29T09:46:12
Published2026-09-30T16:21:20
Patch Date2026-09-29
Last Updated2026-10-02T19:58:23

LINK COPIED TO CLIPBOARD