The Dutch Institute for Vulnerability Disclosure says its own network was compromised through two previously unknown Zammad flaws exploited as a chain. The organization attributes the speed and autonomy of the intrusion to an AI-driven agent that progressed from session takeover to remote code execution and root in seconds. Administrators running vulnerable releases are urged to move to version 7 or disconnect affected instances.

What was compromised

The nonprofit volunteer research collective, working with Merlon Security, linked the intrusion to the open-source ticketing platform. Investigators described the activity as noisy and disordered, with an automated agent advancing on its own without outside guidance. Because that agent recorded its reasoning, the team could piece together the sequence afterward.

The flaws are now tracked as CVE-2026-102489 and CVE-2026-102490. In combination they permitted takeover of user sessions, execution of code remotely, and elevation from the Zammad user to root. DIVD reports the intruder reached additional services and viewed and removed data within seconds through automation. Segmentation plus response measures kept the actor from penetrating further, although inquiry continues and further updates were expected the next day.

Zammad is an open-source AI-powered helpdesk and support ticketing platform for customer inquiries, IT support requests, and internal ticketing, offered self-hosted or hosted. Zammad states on its website that it has over 2,000 customers and 55,000 users, including De’Longhi, Amnesty International, and NextCloud. DIVD said it informed Zammad and is warning operators of exposed deployments.

How the attack works

According to the NVD entry for CVE-2026-102489, Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The same entry notes the vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

Analysis in the Horizon3AI proof-of-concept repository describes CVE-2026-102489 as an unauthenticated remote code execution vulnerability in Zammad that turns a WebSocket information disclosure flaw into authenticated session takeover and arbitrary command execution as the zammad OS user. The root cause involves Sessions::Event::Base, described as a valid Ruby constant that has no run() method. Sending {"event":"base"} over the WebSocket endpoint raises a NoMethodError whose message includes the full receiver inspect — which contains @clients, the live map of every connected user's request context, including their Cookie header.

The documented chain is:

  • Harvest valid _zammad_session cookies from connected users via the WebSocket @clients disclosure.
  • Identify and hijack an authenticated (ideally admin) session.
  • Install a malicious ERB template through the package API, overwriting the password-reset mailer view.
  • Trigger server-side template evaluation via a password reset to execute an arbitrary command, then clean up the installed package.

A separate assessment in the TIER 2 report for CVE-2026-102489 states the vulnerability was actively exploited in the wild to breach DIVD on 2026-09-21, and DIVD subsequently scanned for and notified owners of publicly exposed instances. That report notes Zammad is typically deployed with a public-facing customer portal, classifies impact as high, and records exploitation as requiring passive user interaction (UI:P), with Assessment Tier TIER 2. It also notes DIVD reproduced and analyzed the exploit internally and describes vendor guidance as upgrading to Zammad v7.x or taking the instance offline.

Proof of concept

The Horizon3AI repository provides CVE-2026-102489.py with this usage:


% python3 CVE-2026-102489.py -h
usage: CVE-2026-102489.py [-h] -u URL [-c COMMAND] [--out-file OUT_FILE]

options:
  -h, --help            show this help message and exit
  -u URL, --url URL     The base URL of the target
  -c COMMAND, --command COMMAND
                        Command to execute on the target
  --out-file OUT_FILE   Output file path on the target (default:
                        /tmp/zammad_rce.txt)

Default run against a target:


python3 CVE-2026-102489.py -u http://zammad.example.com

Custom command execution:


python3 CVE-2026-102489.py -u http://zammad.example.com -c 'id'

The default output path on the target is /tmp/zammad_rce.txt. Full root-cause discussion, exploitation details, and indicators of compromise are presented in the Horizon3 attack research disclosure.

Detection and mitigation

DIVD advises Zammad operators to upgrade to version 7, which is considered safe, or take the instance offline as soon as possible. The observatory assessment likewise references upgrading to Zammad v7.x or taking the instance offline, plus a DIVD log verification script for compromise assessment, and notes DIVD scanning and notification of publicly exposed instances.

Operators should inventory internet-facing helpdesk portals, confirm whether releases 6.3.0 to 6.5.4 or 7.0.0 to 7.1.3 are in use, prioritize upgrade of the vulnerable 6.x line, review WebSocket logs and session activity for anomalous disclosure or hijacking, audit package/API activity for unexpected template or mailer-view changes followed by password-reset activity, and look for unexpected files such as /tmp/zammad_rce.txt or unexpected processes running as the zammad user.