Zammad Zero-Day Chain Lets AI Agent Hijack Sessions, Execute Code and Escalate to Root

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


An AI agent breached the Dutch Institute for Vulnerability Disclosure by chaining two previously unknown flaws in Zammad, an open source helpdesk platform.

The September 21, 2026 attack moved from a hijacked session to root access, giving the intruder full control of the server within seconds. DIVD detected the intrusion the following day and blocked access to systems in its data center.

By October 1, investigators had confirmed stolen volunteer email addresses, while possible exposure of contact details, support correspondence, and sensitive research remained under investigation. Researchers from Sysdig examined the incident and highlighted the agent’s rapid, disorderly behavior.

Sysdig said in a report shared with Cyber Security News (CSN) that the attacker left explanatory comments in its scripts and disrupted its own activities, creating evidence that helped investigators recognize the breach.

The incident concerns an AI assisted intrusion, not a newly named malware family.

Sysdig compared its behavior with earlier autonomous attacks, including JADEPUFFER, whose autonomous ransomware attack methods showed how agents can adapt during an intrusion. No human operator or group had been publicly linked to the DIVD attack.

Zammad Zero-Day Chain

The first flaw, CVE-2026-102489, allowed session hijacking followed by remote code execution as the Zammad service account. Sysdig reported a severity score of 8.7 and said exploitation did not require existing privileges. The internet facing application provided the entry point into DIVD’s environment.

As earlier Zammad vulnerability chain coverage explained, versions 6.3.0 through 6.5.4 support the exploitable chain. The first defect also exists in versions 7.0.0 through 7.1.3, but environmental conditions prevent exploitation there.

Whether versions earlier than 6.3.0 are affected remained unknown in Sysdig’s report. The agent then used CVE-2026-102490 to elevate the service account to root.

Sysdig described this local privilege escalation flaw as affecting versions 1.5.0 through 7.1.0-alpha, with a severity score of 8.5. Together, the vulnerabilities received a critical chain score of 9.4.

After gaining control, the attacker attempted password spraying, which tries common passwords across multiple accounts, and an interception attack.

These activities interfered with each other. Its scripts also included comments claiming its actions were harmless, reinforcing investigators’ assessment that an autonomous agent was directing the operation.

Such adaptive behavior also appeared in earlier AI driven database intrusions where agents selected their next actions from previous results.

At DIVD, network segmentation limited further movement, but investigators found signs of compromise in ticketing, project support, and operational systems. Those findings do not establish that every investigated system lost data.

DIVD believed its security response ticket archive had been only partially extracted. That archive could contain vulnerability reports, follow up requests about exposed systems, and credential dump extracts with masked passwords.

Accounting information, bank accounts, and initial security notifications had no known impact in the preliminary findings released publicly.

Detection and containment

Sysdig advised upgrading to Zammad 7.0.0 or later, or taking vulnerable installations offline, while warning that the local escalation issue still required attention.

Subsequent Zammad exploitation warning coverage recommends version 7.2.0 and investigation alongside mitigation. Administrators should not interpret blocking the initial entry point as proof that a host is clean.

Defenders should isolate helpdesk infrastructure, restrict access to internal services, and block outgoing traffic unless explicitly needed.

Preserve application and web server logs before rebuilding systems, then run DIVD’s log checking script. A clean result does not rule out compromise, so unfamiliar processes and files also warrant investigation.

Sysdig recommends monitoring service accounts for unexpected command shells, transitions to root, and connections to unfamiliar destinations.

Investigators should also check for widespread credential file reads, repeated failed logins, and unusually large uploads. Any exploitation evidence should trigger treatment of the server as fully compromised and rotation of accessible credentials.

Because the agent reached root within seconds, Sysdig urged organizations to authorize automated containment for reliable alerts, rather than wait for manual escalation.

Stolen volunteer addresses also create impersonation risks, making suspicious messages another concern while DIVD continues assessing the breach and the extent of data exposure.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post Zammad Zero-Day Chain Lets AI Agent Hijack Sessions, Execute Code and Escalate to Root appeared first on Cyber Security News.