RC RANDOM CHAOS

Two Zammad zero-days let an AI agent reach root

DIVD says two Zammad zero-days let an AI agent hijack a session, reach root, and exfiltrate data in seconds; network segmentation limited the breach.

· 2 min read
Two Zammad zero-days let an AI agent reach root

The Dutch Institute for Vulnerability Disclosure reconstructed the attack on its own network from the attacker’s own notes. The AI agent that ran the intrusion left behind clear explanations of its decisions, step by step, so DIVD could walk back through what it did and why. That record is the unusual part. The chain underneath it is competent but not exotic.

DIVD says two zero-days in the open-source Zammad ticketing system, now tracked as CVE-2026-102489 and CVE-2026-102490, let the attacker hijack a session, run code remotely, and escalate from the Zammad service user to root. In the nonprofit’s words: “Used together, they allowed the attackers to hijack sessions, run code remotely, and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack.” Once at root, the agent reached other services and read and exfiltrated data from DIVD’s systems.

Speed is the point DIVD keeps returning to. Session hijack through to root to data exfiltration happened in seconds, because an agent was driving rather than a human typing commands and waiting on output. DIVD describes the attack as autonomous: the agent moved on its own and chose its next steps without external direction.

It was also, in DIVD’s description, “loud and very, very messy.” An operator pacing a manual intrusion stays quiet to avoid tripping alarms. An agent optimizing for its goal burned through the chain fast and left a trail, including the commentary that made reconstruction possible.

What stopped it was ordinary. DIVD credits network segmentation and its incident response for keeping the threat actor from moving deeper into the network. The investigation is still open.

Zammad is a self-hosted or hosted helpdesk and ticketing platform. Zammad says it has over 2,000 customers and 55,000 users, naming De’Longhi, Amnesty International, and NextCloud. DIVD found the two flaws with Merlon Security, reported them to Zammad, and is now notifying operators of vulnerable instances.

If you run Zammad, the guidance from DIVD is short: upgrade to version 7, which it considers safe, or take the instance offline until you can. In this incident the ticketing system was the way in: a hijacked session there led to root and then to other services on DIVD’s network. The segmentation around it is what kept this from being worse.

DIVD said it would publish more tomorrow.

Share

Keep Reading

Latest on the Wire

Full wire →

New signal daily · RSS

Stay in the loop

New writing delivered when it's ready. No schedule, no spam.