Status: KEV
| Advisory ID: CVE-2026-102490
Key Details
| CVE | CVE-2026-102490 |
| Affected products | Zammad GmbH Zammad |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-269 (Improper Privilege Management) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-10-02. |
| Federal remediation deadline | 2026-10-05 (CISA KEV, Binding Operational Directive). |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489. (CISA)
What to Do
Monitor Zammad GmbH's web page for any future patch releases.
References
KEV Required Action