PULSE
FEED
ransomqilin reclama a Thai Lion Air · TH · Transportationransomrhysida reclama a Mat Bao Corporation · VN · Technologyransompanzer reclama a Paessolucoes · BR · Otherransomrhysida reclama a Electro Heat Sweden AB · SE · Energy & Utilitiesransomqilin reclama a Sports Events365 · GB · Hospitalityransomauditteam reclama a Ad***ng · AE · Technologyransomakira reclama a The Official College of Architects of León (COAL) · MX · Professional Servicesransomakira reclama a Jampac Alimentos · BR · Agriculture and Food Productionransomakira reclama a Pacific Tank Lines · US · Transportationransomqilin reclama a Inova Semiconductors GmbH · DE · Manufacturingransombooba project reclama a Raleigh Family Medicine · US · Healthcareransombooba project reclama a EdgeEndo® USA · US · Healthcareransombooba project reclama a Soni Medical Centre · CA · Healthcareransombooba project reclama a University of Illinois Chicago · US · Educationransomqilin reclama a Thai Lion Air · TH · Transportationransomrhysida reclama a Mat Bao Corporation · VN · Technologyransompanzer reclama a Paessolucoes · BR · Otherransomrhysida reclama a Electro Heat Sweden AB · SE · Energy & Utilitiesransomqilin reclama a Sports Events365 · GB · Hospitalityransomauditteam reclama a Ad***ng · AE · Technologyransomakira reclama a The Official College of Architects of León (COAL) · MX · Professional Servicesransomakira reclama a Jampac Alimentos · BR · Agriculture and Food Productionransomakira reclama a Pacific Tank Lines · US · Transportationransomqilin reclama a Inova Semiconductors GmbH · DE · Manufacturingransombooba project reclama a Raleigh Family Medicine · US · Healthcareransombooba project reclama a EdgeEndo® USA · US · Healthcareransombooba project reclama a Soni Medical Centre · CA · Healthcareransombooba project reclama a University of Illinois Chicago · US · Education
← Todos los CVEs
CVE Watch2 oct 2026

CVE-2026-102490

Zammad GmbH Zammad Improper Privilege Management Vulnerability

CVSS

9.8

Crítico

EPSS

0.3%

p16

KEV

SÍ

2 oct 2026

Exploit Today

55

0-100

Publicado: 30 sept 2026 · Última mod.: 2 oct 2026 · CWE-269

EPSS · 30d
0.3%EPSS · 30 días0.3%
2026-10-012026-10-02
Ficha del catálogo KEV

Producto

Zammad GmbH / Zammad

Vulnerabilidad

Zammad GmbH Zammad Improper Privilege Management Vulnerability

Añadido a KEV

2 oct 2026

Remediar antes de

5 oct 2026

Uso conocido en ransomware

No

Descripción resumida

Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.

Acción requerida

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Notas

https://zammad.com/en/product/releases/ ; https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297/2 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-102490

Descripción técnica

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-104854—
—
——0Nx is a monorepo solution for TypeScript and polyglot codebases. From 14.6.0 until 22.7.9 and 23.1.2, Nx creates Unix domain sockets for its daemon and isolated plugin workers in shared temporary locations without owner-only directory and socket permissions. Another unprivileged local account on a shared build server, developer host, or multi-user container can discover and connect to a running socket because the transport performs no authentication and relies on filesystem containment. The daemon's PROCESS_IN_BACKGROUND request accepts a module path and invokes its default export, allowing a caller that controls a file to execute code as the account running Nx; other handlers can expose workspace file contents, project graphs, and task hashes. Disabling the daemon alone does not remove the vulnerable plugin-worker sockets, while single-user machines without another local account are not exposed. This issue is fixed in versions 22.7.9 and 23.1.2.10h
CVE-2026-196529.8 CRÍ
—
——0The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowed roles. This makes it possible for unauthenticated attackers to register a new account with the administrator role by submitting a locally computed bcrypt hash of `administrator` as `form_id`, and when `auto_login=on` is submitted, be immediately authenticated as that administrator in the same request, resulting in full site takeover. Exploitation requires a WordPress nonce, but that nonce is publicly emitted on any page rendering the Divi Membership registration form and is therefore obtainable by any unauthenticated visitor.10h
CVE-2026-1044124.3 MED
—
——0Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the Editor or Super Editor role to assign their own role to other staff despite lacking permission to do so. An authenticated Editor or Super Editor can promote Author and Contributor users to Editor or Super Editor.10h
CVE-2026-158978.8 ALT
20.9%
——6The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function, in its register_login_action='update' flow, trusting an attacker-supplied user_id value and passing it to wp_update_user() without any ownership or capability check. Because the super_save_form AJAX action also enforces no capability check, any authenticated user with Subscriber-level access and above can create the required malicious form (register_login_action='update' with register_login_user_id_update='true') and then submit it with user_id set to an administrator's ID along with a new user_pass/user_email. This makes it possible for authenticated attackers with Subscriber-level access and above to overwrite the credentials of arbitrary existing accounts — including administrators — resulting in account takeover and full site compromise.15h
CVE-2026-27872—
0.3%
——0- Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force). This issue affects Easy IO FG: before 2.0b52.10h
CVE-2026-1040188.8 ALT
48.6%
——15An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7 when configured to enforce per-user command privileges. Under certain shell operations, a command may be evaluated without the privilege check that is normally applied, allowing an authenticated user with limited privileges to execute commands they are not authorized to run. Successful exploitation can result in privilege escalation, with impact to the confidentiality, integrity, and availability of the affected device. The issue affects all versions of VxWorks 7 prior to 26.09.  It has been fixed in 26.09.10h