First published · Last updated
CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability
Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. The excerpt directs applying vendor mitigations and following CISA’s BOD 26-04 guidance and forensics triage requirements.
Categories: technology
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 6/10
- Geographic reach
- 1/10
- Global importance
- 3/10
- Impact magnitude
- 5/10
- Positivity
- 2/10
- Urgency
- 6/10
Why it matters
Mitigations and compliance with CISA guidance are required to address a vulnerability that permits local privilege escalation.

