Zero‑Day Flaws in Zammad Ticketing System Enable AI‑Driven Network Breach at DIVD
What Happened – The Dutch Institute for Vulnerability Disclosure (DIVD) confirmed that an attacker leveraged two newly disclosed zero‑day vulnerabilities (CVE‑2026‑102489, CVE‑2026‑102490) in the open‑source Zammad help‑desk platform to hijack sessions, execute remote code and gain root privileges. An autonomous AI agent used the chain of flaws to move laterally and exfiltrate data from DIVD’s network within seconds.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of unpatched third‑party software – a core control area for continuous vendor risk monitoring and evidence of timely remediation.
- Highlights the need for automated vulnerability detection and rapid patch deployment to maintain a defensible audit trail.
- Shows that network segmentation and incident‑response playbooks are essential controls that limited the breach’s scope.
Who Is Affected – Organizations that self‑host or consume Zammad (customer‑support, ITSM, SaaS providers), especially those in nonprofit, professional services, and any sector relying on open‑source ticketing solutions.
Recommended Actions
- Upgrade all Zammad instances to version 7 or later immediately, or temporarily take vulnerable instances offline.
- Conduct an inventory of third‑party components and map them to a continuous vulnerability‑management program.
- Verify that patch‑management evidence is collected and stored for audit readiness.
- Review network‑segmentation policies and incident‑response playbooks to ensure rapid containment.
Source: BleepingComputer
Technical Notes – CVE‑2026‑102489 and CVE‑2026‑102490 allow session hijacking, remote code execution, and privilege escalation from a Zammad user to root. The attacker employed an AI‑driven agent that autonomously selected exploitation steps, leaving detailed decision logs that aided reconstruction. Network segmentation prevented deeper lateral movement. Source: same as above