CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability
High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2026-10-02. EPSS: 0.6% chance of exploitation in the next 30 days.
Zammad packages built with packager.io (DEB and RPM) could have allowed a local attacker who already had file system write privileges as the unprivileged zammad service account to escalate to full root privileges on the host. Service processes began running as root and executed files that were owned and writable by the zammad account before dropping their identity to that account. An attacker holding that foothold could have escalated within seconds, because the affected services were restarted automatically whenever they stopped; no administrator interaction was required. Only installations from the DEB and RPM packages were affected — installations from source or the official container images were not. All released packaged versions were affected.
Affected products
- Zammad Zammad: before 7.2.2 (fixed in 7.2.2)
Published 2026-09-30. Last modified 2026-10-09.