{"id":"CVE-2026-102490","title":"All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.","summary":"All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.","severity":"high","cvss":8.5,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/AU:Y/V:D","vendor":"Zammad GmbH","product":"Zammad","affected":["Zammad >= 1.5.0 < 7.1.0-alpha"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T19:57:08.043","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102490","references":[{"url":"https://csirt.divd.nl/CVE-2026-102490","label":"csirt@divd.nl"},{"url":"https://csirt.divd.nl/DIVD-2026-00015","label":"csirt@divd.nl"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-09-30T17:13:20.840Z","slug":"CVE-2026-102490","body":"## Overview\n\nAll versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":46.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}