Zammad — AI-Driven Network Breach Enabled by Chained Zero-Day Vulnerabilities (CVE-2026-102489)
Publication date: September 30, 2026
Category: Zero Days (realtime trigger)
Introduction
The Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit organization of volunteer security researchers, recently disclosed a breach affecting its internal network infrastructure. The incident stood out due to the nature of the attack: it was executed and coordinated entirely in an autonomous manner by an artificial intelligence agent capable of making real-time decisions without external human intervention. The intrusion relied on the chained exploitation of two zero-day vulnerabilities affecting Zammad, a popular open-source ticketing system, which were discovered by DIVD in collaboration with Merlon Security.
What is Zammad and the Exploited Vulnerabilities? (General Analysis)
Zammad is a web-based open-source helpdesk and customer support ticketing platform utilized in both self-hosted and managed service deployments to manage customer inquiries, IT support requests, and corporate communications. Because it centralizes sensitive communications and operational data, compromising such a platform presents a critical security risk to enterprise and institutional environments.
The attack leveraged two officially identified critical vulnerabilities in tandem:
- CVE-2026-102489 (Confirmed Fact - NVD): A session hijacking vulnerability affecting Zammad versions 6.3.0 through 6.5.4, as well as versions 7.0.0 to 7.1.3 (though unexploitable in the latter range due to environmental conditions). It leads to remote code execution (RCE) under the privileges of the
zammaduser.- Official CVSS v4.0 Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:X— 9.4 (Critical).
- Official CVSS v4.0 Vector:
- CVE-2026-102490 (Confirmed Fact - NVD): A local privilege escalation vulnerability allowing the local
zammaduser to escalate privileges to root across all versions of Zammad, including the latest alpha releases.- Official CVSS v4.0 Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:X— 9.4 (Critical).
- Official CVSS v4.0 Vector:
How Does It Work? (Technical Analysis)
The incident is notable for the speed and operational autonomy demonstrated by the threat actor’s artificial intelligence agent. The technical attack flow progressed through several distinct stages:
- Initial Access and Session Hijacking: Utilizing the vector provided by CVE-2026-102489, the AI agent manipulated authentication and session handling mechanisms within the Zammad application, successfully bypassing standard access controls and hijacking an active session without prior valid credentials.
- Remote Code Execution (RCE): Leveraging the compromised session, the flaw enabled the injection and execution of arbitrary remote commands under the security context of the service’s operating system user (
zammad). - Local Privilege Escalation: Immediately after gaining execution as the
zammaduser, the automated agent triggered the second vulnerability (CVE-2026-102490), achieving an instant vertical privilege escalation to the highest system privilege level (root). - Machine-Speed Exfiltration: Once full administrative control of the server was secured, the AI agent autonomously evaluated its next objectives, accessed adjacent network services, and proceeded to read and exfiltrate corporate data within seconds, leaving behind detailed internal decision logs.
Affected Systems / Environments
The potential impact of these vulnerabilities spans a vast global deployment base, given that Zammad reports over 2,000 enterprise customers and 55,000 active users, including major international organizations and multinational corporations.
| CVE | Category (CWE) | Impact | CVSS v4.0 | Vector (summary) |
|---|---|---|---|---|
| CVE-2026-102489 | Not reported by NVD | Session hijacking & RCE | 9.4 (Critical) | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/... |
| CVE-2026-102490 | Not reported by NVD | Escalation to root |
9.4 (Critical) | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/... |
- Vulnerable Versions (CVE-2026-102489): Zammad versions 6.3.0 through 6.5.4, and versions 7.0.0 to 7.1.3 (unexploitable under specific environment configurations).
- Vulnerable Versions (CVE-2026-102490): All Zammad versions, including pre-patch alpha development branches.
Mitigation and Detection
Remediation
- Priority Upgrading: Strongly recommended that Zammad deployments be upgraded to version 7 or later, which contains necessary fixes against this exploitation chain.
- Temporary Disconnection: If immediate patching is not feasible, administrators should take vulnerable Zammad instances offline from public networks or halt the service until remediation can be applied.
- Network Segmentation: Ensure that customer support servers are strictly segmented from the core corporate network to restrict lateral movement in the event of a compromise.
Detection
- Application and System Log Monitoring: Inspect logs for anomalies in Zammad session creation, sudden execution of operating system commands originating from web worker processes, and unusual privilege modifications of local accounts toward
root. - Network Traffic Auditing: Monitor for patterns of mass automated queries or abrupt data exfiltration immediately following anomalous HTTP requests.
“Used together, they allowed the attackers to hijack sessions, run code remotely, and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack.” — DIVD
Wrapping Up
The incident reported by DIVD establishes a critical milestone in threat evolution by highlighting the operational deployment of artificial intelligence agents capable of orchestrating zero-day attacks at machine speed. The combination of CVE-2026-102489 and CVE-2026-102490 illustrates that traditional human-driven defensive response times are no longer sufficient against automated autonomous threats. Prompt mitigation via upgrading to Zammad version 7 and rigorous network segmentation remain indispensable safeguards for securing organizational assets.
References
- BleepingComputer. (2026). DIVD says Zammad zero-days enabled AI-driven network breach. https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/
- Dutch Institute for Vulnerability Disclosure (DIVD). Advisory: CVE-2026-102489. https://csirt.divd.nl/CVE-2026-102489
- Dutch Institute for Vulnerability Disclosure (DIVD). Advisory: CVE-2026-102490. https://csirt.divd.nl/CVE-2026-102490
- Dutch Institute for Vulnerability Disclosure (DIVD). Incident Case DIVD-2026-00015. https://csirt.divd.nl/DIVD-2026-00015