CISA Flags CVE-2026-102490 Zammad Root Escalation
CISA added CVE-2026-102490 to its KEV catalog: a local privilege flaw in Zammad that lets the zammad service account escalate to root, chainable with CVE-2026-102489.

Executive Summary
CISA has added CVE-2026-102490, an improper privilege management flaw in Zammad GmbH's Zammad helpdesk and ticketing platform, to its Known Exploited Vulnerabilities (KEV) catalog. According to the KEV entry, the vulnerability allows the local zammad service account to escalate privileges to root, and it can be chained with CVE-2026-102489. Federal civilian agencies are required to apply mitigations by 2026-10-05 under Binding Operational Directive 26-04.
The practical takeaway for defenders is narrow but urgent: any Zammad deployment that grants the zammad service account shell access to its host — the default posture for self-hosted installs — is exposed to a local-to-root escalation path. The KEV listing does not publish a CVSS score, a fixed version, or a vendor advisory URL, so patch status must be confirmed directly with Zammad GmbH. The 2026-10-05 due date is three days from today, which is unusually short and reflects CISA's assessment that the flaw is being actively exploited.
Technical Analysis
The KEV entry describes CVE-2026-102490 as "improper privilege management" — CWE-269 — in Zammad. In plain terms, the zammad user, which runs the Rails application and its background workers, can perform actions that should require root. The KEV text states the impact directly: "can allow the local zammad user to escalate privileges to root."
The entry further notes that CVE-2026-102490 "can be chained with CVE-2026-102489." CISA does not describe the role of CVE-2026-102489 in the chain, and no separate KEV entry for that CVE appears in the catalog excerpt reviewed for this article. The most plausible reading — consistent with how privilege-escalation chains are typically structured — is that CVE-2026-102489 provides an initial foothold or a second privilege boundary crossing that CVE-2026-102490 then completes. ZCyberNews has not independently verified the mechanics of the chain and is flagging this as an open question.
Zammad is a widely deployed open-source helpdesk and ticketing system used by enterprises, government agencies, and managed service providers. Self-hosted deployments typically run the application under a dedicated zammad Unix account, with the web tier and background workers sharing that identity. That architecture is exactly the precondition the KEV entry describes: a local zammad user with the ability to reach a root boundary. Containerized deployments that run the application as a non-privileged user inside a namespace, or that drop capabilities, may reduce exposure — but the KEV entry does not carve out any deployment model, and CISA's remediation requirement is not scoped to a specific configuration.
The KEV entry does not name a threat actor, a campaign, or a set of indicators. CISA's KEV program does not require attribution; inclusion means only that CISA has "evidence of active exploitation." Readers should not infer a specific APT or ransomware group from the listing alone.
Mitigations & Recommendations
CISA's required action for CVE-2026-102490 is to "apply mitigations in accordance with vendor instructions" and to comply with BOD 26-04, which directs agencies to prioritize security updates based on risk. The KEV entry also points to CISA's "Forensics Triage Requirements" — agencies that cannot remediate by the deadline must follow the triage guidance, and for cloud-hosted Zammad instances, BOD 26-04 requires either applying the vendor's cloud mitigations or discontinuing use of the product.
Because the KEV entry does not publish a fixed version or a vendor advisory URL, the first operational step is to obtain Zammad's current security advisory and confirm whether the installed release is affected. Zammad GmbH publishes release notes and security advisories through its own channels; administrators running self-hosted instances should check the project's advisory feed directly rather than relying on the KEV entry, which is a catalog record and not a patch notice.
For defenders who cannot patch before the deadline, the KEV entry's own guidance is to evaluate each asset's internet exposure. A Zammad instance reachable from the internet is the higher-priority target; an internal-only deployment still carries the local-escalation risk if an attacker already has a foothold on the host. Restricting shell access to the zammad account, running the application in a container with a read-only root filesystem and dropped capabilities, and monitoring for unexpected sudo or su invocations from the zammad UID are the controls most directly aimed at this vulnerability class. CISA's Forensics Triage Requirements apply to agencies that miss the deadline and should be read alongside the vendor advisory, not instead of it.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.

