Zammad — AI Agent Chains Zero-Days To Take Over Systems in Seconds (CVE-2026-102489)

Publication date: October 01, 2026
Category: Zero Days / Threat Intelligence

Introduction

The Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit organization of volunteer security researchers dedicated to responsible disclosure, recently suffered a security breach within its own internal infrastructure. Ironically, attackers managed to compromise DIVD’s systems by leveraging two previously unknown zero-day vulnerabilities in Zammad, an open-source helpdesk ticketing platform utilized internally by the organization. Working alongside Merlon Security, DIVD identified the flaws tracked as CVE-2026-102489 and CVE-2026-102490. What makes this attack exceptional is not only the critical nature of the flaws, but the ultrasonic speed of execution: an artificial intelligence agent orchestrated the exploitation within seconds, making autonomous decisions to transition from initial access to root privileges without human intervention.

What is Zammad and the Involved Vulnerabilities? (General Analysis)

Zammad is an open-source customer support and ticket management web platform widely deployed in corporate and research environments to centralize communication channels (email, chat, social media). Because it handles massive volumes of sensitive support metadata and operational records, a compromise of this component serves as a critical entry vector into any organization’s internal network.

Two critical flaws were identified and confirmed within the application architecture during this incident:

  • CVE-2026-102489: A session hijacking vulnerability present in Zammad versions 6.3.0 through 6.5.4, which directly leads to remote code execution (RCE) under the privileges of the zammad operating system user. (Note: Versions 7.0.0 through 7.1.3 also contain the affected code, but are not exploitable due to environmental conditions).
    • Official NVD CVSS v4.0 Score and Vector: 9.4 (CRITICAL) — CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:X
  • CVE-2026-102490: A local privilege escalation vulnerability affecting all versions of Zammad (including the latest alpha builds), enabling the local zammad user to successfully elevate privileges all the way to root.
    • Official NVD CVSS v4.0 Score and Vector: 9.4 (CRITICAL) — CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:X

How Does It Work? (Technical Analysis)

The attack mechanism highlights a paradigm shift in offensive operations: the integration of AI-driven autonomous agents to execute complex exploitation chains.

  • Initial Entry and Session Hijacking: The attacker (or in this case, the autonomous AI agent) interacts with the externally exposed Zammad web interface. Exploiting the session control flaw (CVE-2026-102489), the agent hijacks an active session or manipulates the authentication flow, allowing command injection or remote code execution (RCE) directly within the context of the operating system user running the application daemon (zammad).
  • Automated Privilege Escalation: Once initial access as the unprivileged zammad user is secured, the AI agent requires no cognitive pauses or human oversight to analyze the local environment. It immediately executes reconnaissance routines and triggers the second vulnerability (CVE-2026-102490), seamlessly bypassing isolation controls to gain superuser (root) privileges within seconds.
  • Pivoting and Data Exfiltration: With full machine-level control as root, the agent proceeded to interact with adjacent services inside DIVD’s internal network. Although rapid response from the incident response team and network segmentation contained the advance, the agent successfully accessed and exfiltrated a portion of data before the affected server was isolated.

“Used together, they allowed the attackers to hijack sessions, run code remotely and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack.”

Affected Systems / Environments

Organizations deploying the Zammad platform for helpdesk management are exposed if operating unpatched versions.

CVE Category / Flaw Type Impact CVSS Vector (summary)
CVE-2026-102489 Session Hijacking / RCE Critical (Code execution as zammad user) 9.4 (CRITICAL) AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVE-2026-102490 Privilege Escalation Critical (Escalation from zammad to root) 9.4 (CRITICAL) AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
  • Affected Software (CVE-2026-102489): Zammad versions 6.3.0 through 6.5.4 (versions 7.0.0 to 7.1.3 contain vulnerable code but are not exploitable due to environmental conditions).
  • Affected Software (CVE-2026-102490): All versions of Zammad, including recent alpha builds.
  • Risk Profile: Helpdesk servers exposed directly to the internet without strict access controls or adequate perimeter segmentation.

Mitigation and Detection

Remediation

  • Priority Update: The Zammad development team and DIVD strongly recommend immediately updating all vulnerable instances to version 7 (considered safe).
  • Emergency Perimeter Isolation: If applying the patch immediately is not technically feasible, the Zammad instance must be disconnected from the internet (taken offline) to mitigate exposure to automated attacks.
  • Log Auditing: DIVD has provided verification tools and scripts for the community to analyze logs in search of anomalies and signs of abuse associated with these zero-days.

Detection

  • Strictly monitor incoming connections to Zammad web endpoints exhibiting anomalous session manipulation patterns or unusual HTTP requests followed by system process execution.
  • Search for traces of high-speed automated activity where queries and local command execution occur within milliseconds, evidencing the use of AI agents or highly optimized attack scripts.
  • Watch for sudden privilege elevation from service daemon accounts to administrative accounts (root).

Wrapping Up

The incident experienced by DIVD marks a critical milestone in the evolution of the threat landscape: the active exploitation of chained zero-day vulnerabilities via autonomous artificial intelligence agents. Far from being a purely theoretical risk, the capability of an AI agent to analyze an environment, chain critical RCE and privilege escalation flaws, and move laterally in seconds demonstrates that Blue Teams must automate their responses at matching speeds. The immediate recommendation for the community is to patch immediately to Zammad version 7 or take exposed services offline.

References