CyberICT

CVE-2026-102490

Zammad GmbH · Published September 30, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

Affected Products

  • Zammad < 7.1.0
  • Zammad

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H