{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-102490",
"assignerOrgId": "b87402ff-ae37-4194-9dae-31abdbd6f217",
"state": "PUBLISHED",
"assignerShortName": "DIVD",
"dateReserved": "2026-09-29T09:46:12.490Z",
"datePublished": "2026-09-30T16:21:20.601Z",
"dateUpdated": "2026-10-08T19:55:53.033Z"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "b87402ff-ae37-4194-9dae-31abdbd6f217",
"shortName": "DIVD",
"dateUpdated": "2026-10-08T19:55:53.033Z"
},
"title": "Local privilege escalation in Zammad v1.5.0 to v7.2.2 installed via DEB or RPM package",
"datePublic": "2026-09-29T20:00:00.000Z",
"affected": [
{
"vendor": "Zammad GmbH",
"product": "Zammad",
"platforms": [
"Linux"
],
"versions": [
{
"status": "affected",
"version": "1.5.0",
"lessThan": "7.2.2",
"versionType": "semver"
},
{
"status": "unknown",
"version": "*",
"lessThan": "1.5.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.2.2",
"lessThan": "*",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
],
"descriptions": [
{
"lang": "en",
"value": "Zammad packages built with packager.io (DEB and RPM) could have allowed a local attacker who already had file system write privileges as the unprivileged zammad service account to escalate to full root privileges on the host. Service processes began running as root and executed files that were owned and writable by the zammad account before dropping their identity to that account. An attacker holding that foothold could have escalated within seconds, because the affected services were restarted automatically whenever they stopped; no administrator interaction was required. Only installations from the DEB and RPM packages were affected — installations from source or the official container images were not. All released packaged versions were affected.",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "Zammad packages built with packager.io (DEB and RPM) could have allowed a local attacker who already had file system write privileges as the unprivileged zammad service account to escalate to full root privileges on the host. Service processes began running as root and executed files that were owned and writable by the zammad account before dropping their identity to that account. An attacker holding that foothold could have escalated within seconds, because the affected services were restarted automatically whenever they stopped; no administrator interaction was required. Only installations from the DEB and RPM packages were affected — installations from source or the official container images were not. All released packaged versions were affected."
}
]
}
],
"tags": [
"x_known-exploited-vulnerability",
"x_open-source"
],
"references": [
{
"url": "https://csirt.divd.nl/DIVD-2026-00015",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://csirt.divd.nl/CVE-2026-102490",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://zammad.com/en/advisories/cve-2026-102489-cve-2026-102490",
"tags": [
"vendor-advisory"
]
},
{
"url": "https://github.com/zammad/zammad/security/advisories/GHSA-p97w-927q-8vxq",
"tags": [
"vendor-advisory",
"technical-description"
]
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
],
"cvssV4_0": {
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"vulnConfidentialityImpact": "HIGH",
"subConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"subIntegrityImpact": "NONE",
"vulnAvailabilityImpact": "HIGH",
"subAvailabilityImpact": "NONE",
"exploitMaturity": "ATTACKED",
"Safety": "NOT_DEFINED",
"Automatable": "YES",
"Recovery": "NOT_DEFINED",
"valueDensity": "DIFFUSE",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"version": "4.0",
"baseSeverity": "HIGH",
"baseScore": 8.5,
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/AU:Y/V:D"
}
},
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "Chained with CVE-2026-102489"
}
],
"cvssV4_0": {
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"userInteraction": "PASSIVE",
"vulnConfidentialityImpact": "HIGH",
"subConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"vulnAvailabilityImpact": "HIGH",
"subAvailabilityImpact": "HIGH",
"exploitMaturity": "ATTACKED",
"Safety": "NOT_DEFINED",
"Automatable": "YES",
"Recovery": "NOT_DEFINED",
"valueDensity": "CONCENTRATED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"version": "4.0",
"baseSeverity": "CRITICAL",
"baseScore": 9.4,
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/V:C"
}
}
],
"credits": [
{
"lang": "en",
"value": "Earth Grob (Merlon Security)",
"type": "finder"
},
{
"lang": "en",
"value": "Luke Paris (Merlon Security)",
"type": "finder"
},
{
"lang": "en",
"value": "Tijmen van der Spijk (Merlon Security)",
"type": "finder"
},
{
"lang": "en",
"value": "Zohar Cochavi (Merlon Security)",
"type": "finder"
},
{
"lang": "en",
"value": "Alje Woltjer (Merlon Security)",
"type": "finder"
},
{
"lang": "en",
"value": "Mischa Rick van Geelen (DIVD)",
"type": "finder"
},
{
"lang": "en",
"value": "Ralph Horn (DIVD)",
"type": "finder"
},
{
"lang": "en",
"value": "Max van der Horst (DIVD)",
"type": "finder"
},
{
"lang": "en",
"value": "Victor Pasman (DIVD)",
"type": "analyst"
},
{
"lang": "en",
"value": "Frank Breedijk (DIVD)",
"type": "analyst"
},
{
"lang": "en",
"value": "Zammad",
"type": "remediation developer"
}
],
"source": {
"advisory": "DIVD-2026-00015",
"discovery": "INTERNAL"
},
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
},
"adp": [
{
"metrics": [
{
"other": {
"type": "ssvc",
"content": {
"timestamp": "2026-10-02T00:00:00+00:00",
"options": [
{
"Exploitation": "active"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"version": "2.0.3",
"id": "CVE-2026-102490"
}
}
},
{
"other": {
"type": "kev",
"content": {
"dateAdded": "2026-10-02",
"reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-102490"
}
}
}
],
"references": [
{
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-102490",
"tags": [
"government-resource"
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"type": "CWE",
"cweId": "CWE-269",
"description": "CWE-269 Improper Privilege Management"
}
]
}
],
"title": "CISA ADP Vulnrichment",
"providerMetadata": {
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP",
"dateUpdated": "2026-10-03T03:55:35.743Z"
},
"timeline": [
{
"time": "2026-10-02T00:00:00.000Z",
"lang": "en",
"value": "CVE-2026-102490 added to CISA KEV"
}
]
}
]
}
}