CISA has added CVE-2026-102490 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects Zammad GmbH’s Zammad product and is identified as the “Zammad GmbH Zammad Improper Privilege Management Vulnerability”. It allows the local zammad user to escalate privileges to root and can be chained with CVE-2026-102489.
This is an improper privilege management vulnerability involving local privilege escalation. An attacker who can access the local zammad user account may elevate privileges to root, potentially gaining complete control of the affected system. The vulnerability has a CVSS score of 9.4 and is rated Critical. The available data does not confirm whether a patch is available; its patch status is listed as unknown.
CISA’s KEV listing confirms that threat actors are actively exploiting this vulnerability. The available data does not confirm use in ransomware campaigns. Federal Civilian Executive Branch (FCEB) agencies must remediate the vulnerability by 5 October 2026.
CISA requires organisations to apply mitigations in accordance with vendor instructions, while ensuring compliance with BOD 26-04, “Prioritizing Security Updates Based on Risk”, and CISA’s “Forensics Triage Requirements”. Agencies should follow the applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset’s internet exposure and follow BOD 26-04 patching guidance. Although the deadline applies directly to FCEB agencies, all organisations should review their exposure and prioritise remediation.
See the NVD entry for CVE-2026-102490 and CISA’s KEV catalogue for full details: https://nvd.nist.gov/vuln/detail/CVE-2026-102490.