HIGHVulnerability
Verified
Global

CISA KEV: Zammad GmbH Zammad — Zammad GmbH Zammad Improper Privilege Management Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.

Analysis

Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489. Added to CISA Known Exploited Vulnerabilities catalog on 2026-10-02. Remediation due: 2026-10-05.

Indicators of Compromise (2)

CVE (2)
CVE-2026-102489
CVE-2026-102490
Source Attribution

Originally published by CISA KEV on Oct 2, 2026. Verified by: CISA.

Related Threats