Two Zammad Zero-Days Let an AI-Driven Intruder Reach Root on DIVD Systems

DIVD says two Zammad zero-days enabled session hijacking, remote code execution and root escalation in an AI-driven breach. Upgrade to Zammad 7 now.

Two Zammad Zero-Days Let an AI-Driven Intruder Reach Root on DIVD Systems
Vulnerabilities

Illustrative image generated with AI

Listen to this articleAudio edition · 8 min

DIVD links its network breach to a two-flaw exploit chain

The Dutch Institute for Vulnerability Disclosure has attributed a recent network breach to two previously unknown vulnerabilities in Zammad, an open-source platform used for helpdesk and support-ticket operations.

According to reporting on the DIVD investigation, the attacker combined CVE-2026-102489 and CVE-2026-102490 to compromise DIVD’s Zammad environment. The chain allegedly enabled session hijacking, remote code execution and privilege escalation from the Zammad service account to root.

The intruder then reached other services, read information from DIVD systems and exfiltrated data. Network segmentation and the organization’s incident-response actions prevented further movement into the network, DIVD said.

The investigation remained in progress in the cited account. DIVD said it planned to publish another update “tomorrow,” but did not specify an exact publication time.

From a stolen session to root-level control

The two vulnerabilities appear to have played complementary roles rather than producing isolated effects. DIVD described an attack sequence that began with control of an authenticated session and progressed to arbitrary code execution.

From there, the attacker reportedly escaped the limitations of the Zammad account and obtained root privileges. Root access gives a process the highest level of control on a typical Linux system, making the final escalation particularly serious even without a published CVSS score.

The reported chain can be summarized as follows:

  1. Exploitation of the Zammad vulnerabilities enabled session hijacking.
  2. The compromised context was used to execute code remotely.
  3. The attacker escalated from the Zammad account to root.
  4. The intrusion expanded to other services reachable from the affected environment.
  5. Data was accessed and exfiltrated before containment measures restricted further movement.

The available report does not explain which vulnerability enabled each stage, how the session was taken over, or what primitive supported remote execution. It also does not provide proof-of-concept code, request patterns or other exploit mechanics.

That limits defenders’ ability to build vulnerability-specific detections from the public information alone. It does not reduce the reported impact: DIVD says the flaws were successfully combined against its own infrastructure.

DIVD says an AI agent directed the intrusion

A distinctive feature of the incident is DIVD’s assessment that the operation was driven by an AI agent capable of choosing its next actions autonomously.

The organization said the agent moved through exploitation, privilege escalation, service access and data theft within seconds, without external direction during that sequence. DIVD also reported that the system left explanations of its decisions, which investigators used to reconstruct the attack.

This characterization should be kept within the boundaries of DIVD’s findings. The report attributes autonomous decision-making to the agent in this incident; it does not establish how the attacker developed the system, what model it used, or how much preparation occurred before the automated activity began.

The speed is operationally significant. An automated chain that evaluates access and immediately selects follow-on actions can compress several stages of an intrusion into a window too short for manual intervention. Defensive controls therefore need to stop or contain activity automatically, rather than relying exclusively on an analyst noticing and responding to each step.

In this case, segmentation helped limit the outcome. The attacker reached additional services, but DIVD said the controls prevented deeper movement across its network.

Zammad users lack a precise affected-version range

Zammad is available as both a self-hosted and hosted helpdesk platform. It supports customer inquiries, IT support workflows and internal ticket management, making it a potentially valuable target because ticketing systems can hold sensitive conversations and connect to other business services.

The vendor claims more than 2,000 customers and 55,000 users. Organizations named in the report as Zammad users include De’Longhi, Amnesty International and NextCloud. Their appearance in that customer context is not evidence that their systems were targeted or compromised.

The cited disclosure does not identify the vulnerable Zammad releases. It also provides no affected-version range, fixed patch level or product configuration required for exploitation.

Consequently, administrators cannot safely determine exposure merely by comparing their installation against a detailed vulnerable-version list. DIVD’s guidance is broader: upgrade to Zammad version 7, which it considers safe, or take the instance offline as soon as possible.

DIVD said it discovered the vulnerabilities with Merlon Security and notified Zammad. It was also alerting users known to have vulnerable instances.

Immediate defensive priorities for administrators

Zammad operators should treat the upgrade recommendation as the primary response. Systems that cannot be moved promptly to version 7 should be isolated or taken offline, following DIVD’s advice, until they can be secured.

Because the reported compromise included session takeover and root-level execution, simply resetting a password may not address a system that has already been exploited. Administrators should assess the host and connected services for signs of unauthorized access, privilege escalation and data retrieval.

Useful review areas include:

  • Unexpected authenticated sessions or changes in session behavior.
  • Processes launched under the Zammad account that do not match normal application activity.
  • Evidence of commands or processes running with root privileges.
  • Connections from the Zammad host to internal services it does not normally access.
  • Unusual outbound transfers or access to large volumes of ticket and service data.
  • Account, permission or configuration changes made during suspicious activity.

These are general investigation priorities based on the effects described by DIVD, not vulnerability-specific indicators. The cited report supplies no IP addresses, file hashes, domains, log signatures or other concrete indicators of compromise.

Where possible, defenders should preserve system, application, authentication and network logs before rebuilding or taking a suspected host offline. Segmentation between the ticketing server and sensitive internal services can also reduce what an attacker can reach after an initial compromise, as DIVD’s experience demonstrates.

Critical technical questions remain open

The incident establishes a high-impact outcome but leaves several details needed for broader risk assessment unresolved. The cited report contains no CVSS score or formal severity rating, and the exact affected releases are not identified.

There is also no patch-by-patch explanation distinguishing vulnerable and corrected builds. Publicly available details do not show the requests used for exploitation, required access conditions, or artifacts generated by the attack chain.

Nor does the report provide evidence that other Zammad customers were breached. The confirmed scope described here is DIVD’s incident and its attribution of that compromise to the two zero-days.

For now, the combination of session hijacking, remote code execution and escalation to root makes the operational guidance straightforward: move to version 7 or remove the exposed instance from service. Further findings from DIVD and technical information from Zammad will be necessary to narrow the affected population and support precise detection.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →