External risk intelligence

Zammad Privilege Escalation to Root Vulnerability.

CVE advisoryKnown Exploit

CVE-2026-102490

The vulnerability involves a local privilege escalation where an existing local zammad user escalates privileges to root. This requires prior local access to the system and is not reachable via the public internet.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Zammad software that allows a local user to gain elevated root privileges. This issue affects all versions of Zammad.

  • Local users can gain full system control.
  • This grants unauthorized administrative access.
  • Confirm relevance and exposure to Zammad systems.

Attack Path

How an attacker could exploit the issue

An attacker with existing local access to a Zammad system can exploit a privilege escalation flaw. This allows them to elevate their permissions from a standard Zammad user to the root user, gaining complete control over the system.

  • Requires local Zammad user access.
  • Triggered by an improper privilege management flaw.
  • Leads to full system compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow a local user on a Zammad system to gain root privileges. This means an attacker who already has access to the system as the "zammad" user could potentially take full control of the underlying operating system.

  • System control.
  • Local user escalates to root.
  • Complete system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This privilege escalation vulnerability in Zammad impacts the application itself, affecting local users who can gain root access. Application owners or platform teams are likely responsible for managing Zammad instances. The immediate priority is to confirm the presence and reachability of Zammad across the environment, identify the specific instance owners, and then develop a targeted remediation plan based on the business criticality and exposure of each instance.

  • Application owners should manage Zammad instances.
  • Verify all Zammad instances and their exposure.
  • Plan remediation based on risk and criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Zammad and what is it used for?

Zammad is an open-source ticketing system designed to help organizations manage customer support, helpdesk operations, and team communication. It acts as a central hub where incoming queries from various channels like email, chat, or social media are tracked and resolved.

What does CVE-2026-102490 mean by improper privilege management?

This vulnerability belongs to the weakness class of improper privilege management (CWE-269). It means the software does not correctly restrict what a specific user account can do. In this case, the system mistakenly allows a standard 'zammad' user account to perform actions reserved for the root user, which is the highest level of administrative control on a Linux system.

How is this vulnerability triggered?

To trigger the bug, an attacker must already have local access to the system as the 'zammad' user. It is not triggered by simply visiting a website or sending a network request. Without that initial foothold on the local machine, the flaw cannot be exploited to gain root permissions.

Is my Zammad instance at risk if it is internet-facing?

According to Halo Surface Signal, this vulnerability is not directly reachable via the public internet. Because the flaw requires an attacker to already be logged in as a local user, internet-facing access does not change the fundamental requirement of having local system access first.

What should I do first to address this?

Start by identifying all Zammad installations in your environment and confirming the versions in use. Once you have an inventory, work with the relevant application owners to plan for the vendor-recommended updates or patches. Prioritize this based on your organization's internal access controls, ensuring that only trusted personnel have access to the system.

References