Zammad local user to root, exploited (CVE-2026-102490)
CVE-2026-102490
Actively exploited CVE-2026-102490: any local Zammad user escalates to root on all versions including latest alpha (CVSS 9.8). No patch yet; isolate hosts.
Actively exploited in the wild - CVE-2026-102490 is a critical local privilege escalation in all versions of Zammad, including the latest alpha, that grants the local zammad service account full root control of the host. No vendor patch is available yet; treat every Zammad host as compromised-adjacent until a fix ships.
Overview
Zammad is an open-source helpdesk and ticketing platform deployed widely as a web application, often on a dedicated Linux host. CVE-2026-102490 allows any process running as the unprivileged zammad system user to escalate to root. Because the web application itself runs as that user, an attacker who can influence what Zammad executes, or who lands any code execution through a separate vector, immediately inherits a straightforward path to full root on the underlying server.
The CVSS 9.8 rating reflects low attack complexity and no authentication or user interaction requirement once local access as the zammad user is obtained. The scope is universal: release builds and the latest alpha are equally affected, so upgrading within the current line does not remove the exposure. CISA has added this CVE to its Known Exploited Vulnerabilities catalog, confirming observed attacks in the wild.
Impact
Root on a Zammad host is a serious outcome. The platform stores ticket contents, customer email addresses, internal notes, and often credentials for connected mail, chat, and identity systems. Root access also permits lateral movement across the network, persistence via systemd units or cron, and tampering with the application itself to silently harvest future data. Organizations running Zammad in shared infrastructure should assume the entire host, not just the application, is in scope.
Remediation and Mitigation
No patched release exists at the time of writing. Until the vendor ships a fix, prioritize containment:
- Isolate Zammad onto a dedicated host or VM with no inbound trust from production systems, limiting blast radius if escalation occurs.
- Restrict shell and process access for the
zammaduser; remove unnecessary sudo rules and capabilities. - Monitor for unexpected root processes, new systemd units, and outbound connections originating from the Zammad host.
- Apply network egress filtering so a compromised host cannot reach internal management planes.
- Watch the vendor’s release channel and apply the fix immediately when published; validate by re-testing privilege boundaries after upgrade.
Organizations that suspect compromise should preserve logs and review breach reports for patterns seen in similar helpdesk intrusions. Ongoing coverage of exploited CVEs is available in our security news section.
Security Insight
Privilege escalation flaws in web applications are frequently dismissed as low priority because they require a foothold, yet CISA’s KEV listing shows attackers treat them as a decisive second stage. Zammad’s situation is more severe than typical: the vulnerable user is the account the application itself runs as, so application-layer compromise converts directly into host compromise with no additional chaining. Vendors that run their service under a single non-isolated system account keep rediscovering this class of bug, and the correct long-term fix is sandboxing and capability dropping, not just patching the escalation path.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3...
Use after free in Fullscreen in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)...
Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted H...
Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)...