CVE-2026-102490

Published: Set 30, 2026 Last Modified: Set 30, 2026
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 9,4
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

https://csirt.divd.nl/CVE-2026-102490
https://csirt.divd.nl/DIVD-2026-00015