Take care: Local Privilege Escalation (CVE-2026-102490) is reported as being actively exploited

Hi everyone,

We have now received the details of CVE-2026-102490 from DIVD, and we are working on it.

This issue cannot be exploited remotely on its own. An attacker would already need access to your server.

Please update to Zammad 7.2.0 and watch Security Advisories · zammad/zammad · GitHub for updates.

9 Likes