Answer in brief
CVE-2026-102490 records a High severity (CVSS 8.5) vulnerability in Local privilege escalation in Zammad v1.5.0 to v7.2.2 installed via DEB or RPM package. The current sources mark it as known exploited. The current feed maps Zammad GmbH/Zammad (generic), Zammad GmbH/Zammad (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.5. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Zammad GmbH/Zammad (generic), Zammad GmbH/Zammad (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Zammad GmbH/Zammadgeneric | >=1.5.0 <7.2.2 | 7.2.2 |
| Zammad GmbH/Zammadgeneric | >=1.5.0 <7.1.0-alpha | 7.1.0-alpha |
Published upstream
Sep 30, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 30, 2026
Added to CISA KEV
Oct 2, 2026
Evidence: source:kev:kev:kev:recordZammad packages built with packager.io (DEB and RPM) could have allowed a local attacker who already had file system write privileges as the unprivileged zammad service account to escalate to full root privileges on the host. Service processes began running as root and executed files that were owned and writable by the zammad account before dropping their identity to that account. An attacker holding that foothold could have escalated within seconds, because the affected services were restarted automatically whenever they stopped; no administrator interaction was required. Only installations from the DEB and RPM packages were affected — installations from source or the official container images were not. All released packaged versions were affected.
Quoted source text, attributed separately from HOL analysis.