Zammad and AI Ecosystems — Zero-Day Chains, Model Inspection RCE, and Automated Exploitation
Publication date: October 1, 2026
Category: News / Threat Intelligence
Introduction
The global cybersecurity landscape is undergoing a profound transformation driven by automation and the deployment of artificial intelligence agents by threat actors. Recent industry publications and incident response briefings, spearheaded by investigations from Ravie Lakshmanan on The Hacker News, have documented an unusually complex week. Highlights include automated intrusions against the Dutch Institute for Vulnerability Disclosure (DIVD) via a zero-day chain in the Zammad platform (CVE-2026-102489 and CVE-2026-102490), remote code execution triggered by metadata inspection in Unsloth Studio, and the persistence of over half a million active credentials in public GitHub repositories. This analysis examines technical vectors, confirmed vulnerability mechanics, and counter-measures required to mitigate these risks.
What is Zammad and the AI-Assisted Threat Ecosystem? (General Analysis)
Ticketing and customer support platforms like Zammad represent critical components in organizational operational and support infrastructure. Their compromise grants attackers direct visibility over confidential communications, user metadata, and internal credentials.
In this context, offensive automation has evolved: attackers no longer rely exclusively on static scripts, but rather on AI agents capable of closed-loop decision-making, iterating over flaws at machine speed. The vulnerabilities analyzed in Zammad and machine learning libraries such as Unsloth demonstrate that traditional attack surface boundaries have shifted toward auxiliary components previously assumed safe, such as model metadata parsers and incident management systems.
| CVE | Category (CWE) | Impact | CVSS | Vector (summary) |
|---|---|---|---|---|
| CVE-2025-4632 | CWE-22 (Path Traversal) | Critical / File Write & Execution | 9.8 (CRITICAL) | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-102489 | Unreported (NVD) / Session Hijack | Critical / RCE as zammad user | 9.4 (CRITICAL) | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A |
| CVE-2026-102490 | Unreported (NVD) / PrivEsc | Critical / Escalate to Root | 9.4 (CRITICAL) | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A |
(Note: CVE-2025-4632 features vector and severity confirmed by NVD with a CVSS v3.1 score of 9.8. CVE-2026-102489 and CVE-2026-102490 feature official NVD CVSS v4.0 scores of 9.4).
How Does It Work? (Technical Analysis)
Technical analysis of recent incidents reveals sophisticated execution patterns and vulnerability chaining:
- Zammad Zero-Day Chain (CVE-2026-102489 and CVE-2026-102490): The intrusion suffered by DIVD showcased the combined use of two critical vulnerabilities. The first flaw (
CVE-2026-102489) enables session hijacking in Zammad versions 6.3.0 through 6.5.4 (also present in versions 7.0.0 through 7.1.3 under specific conditions), achieving remote code execution (RCE) under the operationalzammaduser context. Immediately following, the second flaw (CVE-2026-102490) allows that local user to escalate privileges toroot. Field reports indicate an AI agent automated this workflow, autonomously determining subsequent actions after each iteration within seconds. - Model Inspection Code Execution (Unsloth Studio): In fine-tuning libraries such as Unsloth, selecting a model in the UI caused the backend to download and execute arbitrary Python code shipped inside the Hugging Face repository. The flaw resided in reading the
config.jsonfile during a simple metadata check—without ever loading weights or performing inference—thereby compromising environment tokens and credentials. - Exploitation and Miner Compilation (CVE-2025-4632): Huntress’s analysis of attacks targeting Samsung MagicINFO illustrates how a Path Traversal flaw (CWE-22) allows writing arbitrary files with system authority. Rather than downloading precompiled cryptominer binaries (bypassing static signatures), operators deployed RMM instances, created administrative accounts, and compiled the miner directly on the compromised host.
Affected Systems / Environments
Identified vectors and vulnerabilities directly impact the following platforms and components:
- Zammad: Versions 6.3.0 to 6.5.4, alongside iterations in branch 7.0.0 to 7.1.3 (affected by session and privilege escalation flaws).
- Samsung MagicINFO Server: Versions prior to 21.1052 (impacted by CVE-2025-4632).
- LLM Development Environments: Unsloth Studio versions prior to 2026.6.9.
- Public GitHub Repositories: Over 543,000 unique credentials exposed in public default branches, many remaining active for years despite GitHub’s push protection mechanisms.
Mitigation and Detection
Remediation
- Immediate Zammad Update: Apply official security patches provided by the Zammad development team to neutralize the session hijacking and root escalation vulnerability chain.
- Samsung MagicINFO Patching: Upgrade MagicINFO servers to version 21.1052 or higher to mitigate CVE-2025-4632 listed in the CISA KEV catalog.
- AI Model Auditing: Update Unsloth Studio to version 2026.6.9 or later and disable automatic metadata loading and inspection of untrusted external repositories.
- Mass Secret Revocation: Conduct code audits utilizing secret scanning tools and immediately revoke any credentials identified within public repositories.
Detection
Defensive teams (Blue Team) must enforce strict monitoring on compiler execution across servers not designated for software development, alongside anomalies in web application sessions and privileged file system calls.
“Offensive automation via artificial intelligence agents drastically narrows the window between zero-day discovery and chained exploitation, requiring security operations teams to adopt automated responses and immediate patching.”
title: Detect Suspicious Compiler Execution on Web Servers
id: 9b2d83f1-4e71-4a12-9c3f-82a12bfa4911
status: experimental
description: Detects unexpected compiler activity (gcc, make, cargo) originating from web application service accounts or ticketing software paths.
references:
- https://www.huntress.com/blog/threat-actor-compiles-cryptominer
- https://csirt.divd.nl/cases/DIVD-2026-00014/
author: Honeynet Analyst Team
date: 2026/10/01
tags:
- attack.execution
- attack.t1106
logsource:
category: process_creation
product: linux
detection:
selection:
ParentImage|endswith:
- /zammad
- /java
- /node
- /python3
Image|endswith:
- /gcc
- /g++
- /make
- /cargo
- /sh
condition: selection
falsepositives:
- Legitimate administrative software builds during maintenance windows.
level: highWrapping Up
This week’s threat bulletin highlights how threat actors continue leveraging a combination of classic flaws (such as path traversal and session weaknesses) alongside emerging attack surfaces tied to the artificial intelligence ecosystem. The velocity with which autonomous agents successfully exploited the zero-day chain in Zammad demonstrates that human operational speed is no longer sufficient to contain automated threats. Rigorous zero-trust adoption, immediate patching of critical components, and strict credential hygiene remain vital pillars for organizational resilience.
References
- Lakshmanan, R. (2026, October 1). ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories. The Hacker News. https://thehackernews.com/2026/10/threatsday-ai-powered-zero-day-chain.html
- DIVD CSIRT. (2026). DIVD Hacked via Zammad 0-Days. DIVD Case Report DIVD-2026-00014. https://csirt.divd.nl/cases/DIVD-2026-00014/
- Pillar Security. (2026). Model Inspection in Unsloth Studio Leads to Critical Arbitrary Code Execution. https://www.pillar.security/blog/look-dont-load-model-inspection-in-unsloth-studio-leads-to-critical-arbitrary-code-execution
- Huntress Security. (2026). Threat Actor Compiles Miner on Infected Host. https://www.huntress.com/blog/threat-actor-compiles-cryptominer
- Truffle Security. (2026). GitHub Repos Expose 543,699 Credentials Nobody Revoked Them. https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them
- National Vulnerability Database. (2025). NVD - CVE-2025-4632. https://nvd.nist.gov/vuln/detail/cve-2025-4632
- National Vulnerability Database. (2026). NVD - CVE-2026-102489. https://nvd.nist.gov/vuln/detail/cve-2026-102489
- National Vulnerability Database. (2026). NVD - CVE-2026-102490. https://nvd.nist.gov/vuln/detail/cve-2026-102490
- Cybersecurity and Infrastructure Security Agency. (2025). CISA Known Exploited Vulnerabilities Catalog - CVE-2025-4632. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-4632