CVE-2026-102490: Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha
Published Sep 30, 2026
·Updated
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
Affected Software
1 affected component
Zammad Zammad>=1.5.0<=7.1.0-alpha
Event History
Sep 30, 2026
CVE Published
via MITRE·04:21 PM
Data Sourced
via MITRE·04:21 PM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverity
Frequently Asked Questions
1
Who is exposed to this issue?
Systems running any affected Zammad version are exposed if a local process or user can operate as the zammad account. The issue allows that local account to escalate privileges to root.
2
Does this require remote access or authentication to Zammad?
The available information describes this as a local privilege-escalation issue. It identifies the local zammad user as the attacker prerequisite and does not state that remote access to the Zammad application alone is sufficient.
3
Are pre-release builds affected?
Yes. The affected range includes Zammad versions from v1.5.0 through v7.1.0-alpha, including the latest alpha.