Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > AI-Driven Zammad Attack Chained Two Zero-Days to Reach Root in Seconds
AI-Driven Zammad Attack Chained Two Zero-Days to Reach Root in Seconds
Read Time:3 Minute, 25 Second

An intruder using an AI agent breached the Dutch Institute for Vulnerability Disclosure by combining two previously unknown weaknesses in Zammad, the open-source helpdesk platform. The September 21 attack progressed from a stolen web session to remote code execution and then root privileges within seconds, illustrating how automated offensive tooling can compress an intrusion timeline faster than a conventional human response process.

DIVD detected the compromise the following day and cut affected systems off from its data center. By October 1, investigators had confirmed the theft of volunteer email addresses. They were still assessing possible access to contact information, support conversations and sensitive security research. No public attribution has tied the activity to a named operator or established threat group.

Two flaws created a complete takeover path

The initial vulnerability, CVE-2026-102489, enabled session hijacking followed by code execution as the Zammad service account. Sysdig assigned the flaw a severity score of 8.7 and reported that the attack did not require existing privileges. Because the helpdesk was exposed to the internet, it provided the agent with a direct entry point into DIVD’s environment.

The second issue, CVE-2026-102490, allowed the service account to elevate its privileges locally to root. It received a score of 8.5, while the combined chain was assessed at a critical 9.4. The exploitable chain affects Zammad 6.3.0 through 6.5.4. The first weakness also exists in versions 7.0.0 through 7.1.3, although reported environmental conditions prevent the same exploitation route there. The privilege-escalation issue spans versions 1.5.0 through 7.1.0-alpha.

Automation was fast, adaptive and noisy

Investigators described the agent’s behavior as rapid but disorderly. After obtaining root, it attempted password spraying across accounts as well as an interception technique, yet the two activities interfered with each other. Scripts left behind explanatory comments, including claims that the activity was harmless. Those artifacts and operational mistakes helped responders identify and reconstruct the intrusion.

The mixed performance is important. AI-driven attacks do not need flawless reasoning to be dangerous; they can compensate with speed, persistence and the ability to select follow-up actions from previous results. At the same time, noisy execution can create valuable detection opportunities. In this case, network segmentation limited further movement even after the public-facing server had been completely compromised.

Potential exposure extends beyond email addresses

DIVD found compromise indicators in ticketing, project-support and operational systems, though that does not prove every investigated system lost data. The organization believes its archive of security-response tickets was only partially extracted. Such records can contain vulnerability submissions, communications with owners of exposed systems and extracts from credential dumps, even when passwords are masked.

Preliminary findings indicated no known impact to accounting details, bank accounts or the initial intake of security notifications. Nevertheless, stolen volunteer addresses can support convincing impersonation attempts. People who work with DIVD should treat unexpected requests, links and document shares with additional caution while the investigation continues.

Containment must match machine-speed intrusion

Administrators should move to Zammad 7.2.0 or the vendor’s latest safe release and investigate systems rather than treating an upgrade as proof they were never compromised. Vulnerable instances that cannot be updated should be removed from exposure. Application and web logs need to be preserved before rebuilding, and DIVD’s log-checking utility can support triage, although a clean result cannot rule out intrusion.

  • Watch service accounts for unexpected shells and transitions to root.
  • Alert on unusual outbound connections and unexpectedly large uploads.
  • Investigate broad credential-file reads and bursts of failed logins.
  • Rotate every credential that the helpdesk host could access after confirmed exploitation.
  • Restrict helpdesk connectivity to internal services and allow outbound traffic only when required.

Once exploitation evidence is present, responders should treat the server as fully controlled by the attacker. The speed of this chain also supports carefully governed automated containment for high-confidence alerts. Waiting for manual escalation may leave an AI agent enough time to complete privilege escalation and data collection before an analyst even opens the case.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on AI-Driven Zammad Attack Chained Two Zero-Days to Reach Root in Seconds, use the discussion on Forum.

>> forum community

Comments

Leave a Reply