{"slug": "zammad-cve-2026-102489-ai-agent-gets-root-patch-now", "title": "Zammad CVE-2026-102489: AI Agent Gets Root — Patch Now", "summary": "CISA added two Zammad zero-days to its Known Exploited Vulnerabilities catalog on October 2 with an October 5 remediation deadline after an AI agent used them to breach the Dutch Institute for Vulnerability Disclosure on September 21. CVE-2026-102489 (CVSS 9.8) is a session-fixation flaw in Zammad 6.3.0 through 6.5.4 that lets an unauthenticated internet attacker execute code as the zammad service user, and CVE-2026-102490 (CVSS 9.8) is a local privilege escalation affecting Zammad 1.5.0 through 7.1.0-alpha that takes that user to root; DIVD said \"The modus operandi indicates an agentic AI powered attack, something we had not seen before.\" Zammad 7.2.0, released September 23, 2026, fixes both flaws, and any instance below 7.2.0 should be upgraded or taken offline.", "body_md": "An AI agent used two zero-days in Zammad — the open-source helpdesk that developer teams self-host as a free Zendesk alternative — to compromise the Dutch Institute for Vulnerability Disclosure, the security research organization that finds and discloses bugs to protect everyone else. On October 2, CISA added both CVEs to its [Known Exploited Vulnerabilities catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) with a mandatory remediation deadline of October 5. If you run any version of Zammad below 7.2.0, you are exposed right now.\n\n## What Zammad Is (and Why Developers Use It)\n\nZammad is an open-source, self-hosted ticketing and helpdesk platform used by developer teams, public sector organizations, and enterprises who want Zendesk-level capability without the SaaS price tag or the data-sharing anxiety. It handles support requests across email, chat, and social channels, ships with LDAP and SAML support, SLA tracking, and full-text search — all free, all self-hosted. The trade-off is that you own the security.\n\n## Two CVEs, One Two-Second Attack Path to Root\n\n**CVE-2026-102489** (CVSS 9.8 Critical) is a session-fixation flaw in Zammad 6.3.0 through 6.5.4. An unauthenticated attacker on the internet can hijack a session and execute code as the `zammad` service user. No credentials, no phishing, no prior access. The flaw also exists in versions 7.0.0 through 7.1.3, though environmental conditions prevent exploitation there.\n\n**CVE-2026-102490** (CVSS 9.8 Critical) is a local privilege escalation flaw that lets the `zammad` service user become root. It affects Zammad 1.5.0 through 7.1.0-alpha — which is effectively every version of Zammad ever shipped. The vendor disputes the scope, but CISA is not interested in the dispute: the deadline stands.\n\nChain them together and the math is grim: an anonymous internet user becomes root on your server in seconds. DIVD’s forensics confirmed the full escalation happened that fast. No persistence phase, no slow lateral movement — just root, immediately.\n\n## The DIVD Breach: An AI Agent Hacked the Hackers\n\nOn September 21, an attacker compromised DIVD’s Zammad installation and walked through the organization’s ticketing data, volunteer email addresses, project management systems, and research databases. DIVD detected the intrusion on September 22 and blocked access to its data center systems.\n\nWhat makes this incident technically notable is how the attacker moved. DIVD’s incident response team concluded it was not a human operator. The attack “was not pre-planned” — the agent selected its next step after each action at machine speed. The exploit scripts left behind self-documenting comments, a signature characteristic of AI-generated code. The attack was also operationally noisy: password spraying and a man-in-the-middle attempt ran concurrently and disrupted each other, something no experienced human attacker would allow. DIVD’s statement: “The modus operandi indicates an agentic AI powered attack, something we had not seen before.”\n\nThe irony of a security research organization being the zero-day proving ground is not subtle. It is, however, instructive: if DIVD ran vulnerable Zammad, your team almost certainly has something comparable in its stack.\n\n## Fix: Upgrade to 7.2.0 Now\n\nZammad 7.2.0 shipped on September 23, 2026 — eleven days before CISA added these CVEs to the KEV catalog. The fix was already available before the attack became public knowledge. Upgrade immediately.\n\n- **Standard install:** Follow the[Zammad 7.2 upgrade guide](https://zammad.com/en/product/releases/7-2)\n- **Docker Compose:** Pull the updated image from the official repository\n- **NixOS:** PR #568263 is in nixpkgs; pin to 7.2.0\n- **If you cannot upgrade immediately:** Take Zammad offline. An exposed instance is worse than a temporarily unavailable one.\n\nFor CVE-2026-102490, there is no confirmed standalone patch outside of 7.2.0’s hardening changes. Treat any instance below 7.2.0 as fully compromised if it was reachable from the internet.\n\n## Detecting Prior Compromise\n\nCISA’s addition to KEV includes a forensic-triage flag: organizations should investigate for prior compromise before simply patching and moving on. If your Zammad instance was internet-facing and ran a vulnerable version, assume it was hit and investigate.\n\nBehavioral indicators to look for in your logs:\n\n- `zammad` service account processes spawning interactive shells or unexpected child processes\n- Sessions authenticated from IP addresses not seen in prior login history\n- Setuid or setgid system calls originating from the application process tree\n- Root-owned processes appearing as children of the Zammad worker process\n- Bursts of authentication failures across multiple accounts in a short window\n- Outbound connections from your helpdesk server to previously unseen external destinations\n\n[RunZero users can identify exposed Zammad installations](https://www.runzero.com/blog/zammad/) in their network using the query: `_asset.protocol:=http AND protocol:=http AND favicon.ico.image.mmh3:=\"-1687285536\"`. DIVD has also [published its full case file](https://csirt.divd.nl/cases/DIVD-2026-00014/), including an IOC check script for CVE-2026-102489 exploitation.\n\n## The Pattern Is Clear\n\nThis is the third self-hosted open-source developer tool added to the CISA KEV catalog in two weeks — Kestra, LiteLLM, and now Zammad. The pattern is not coincidence. Developer tools that teams self-host often have fewer enterprise controls, smaller security teams, and slower patch cycles than commercial SaaS alternatives. They are soft targets. And autonomous AI agents, loud and messy as they are, can exploit faster than any incident response team can react.\n\nThe good news from the DIVD breach: the attack was caught because it was noisy, and network segmentation contained it. Runtime behavioral monitoring — watching for service accounts doing things service accounts do not do — is what caught it. That is worth adding to your runbook. Sysdig’s post-breach [detection guide for the DIVD incident](https://webflow.sysdig.com/blog/ai-agent-exploits-zammad-zero-days-in-divd-breach-what-we-know-and-how-to-detect-it) is a useful starting point.\n\nPatch Zammad now. Check your logs. The CISA KEV deadline is October 5. That is not a suggestion for anyone running internet-facing infrastructure.", "url": "https://wpnews.pro/news/zammad-cve-2026-102489-ai-agent-gets-root-patch-now", "canonical_source": "https://byteiota.com/zammad-cve-2026-102489-rce-patch-now/", "published_at": "2026-10-04 05:13:01+00:00", "updated_at": "2026-10-04 05:37:00.022929+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "ai-policy"], "entities": ["Zammad", "CISA", "Dutch Institute for Vulnerability Disclosure", "CVE-2026-102489", "CVE-2026-102490", "Zammad 7.2.0", "Known Exploited Vulnerabilities catalog"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/zammad-cve-2026-102489-ai-agent-gets-root-patch-now", "markdown": "https://wpnews.pro/news/zammad-cve-2026-102489-ai-agent-gets-root-patch-now.md", "text": "https://wpnews.pro/news/zammad-cve-2026-102489-ai-agent-gets-root-patch-now.txt", "jsonld": "https://wpnews.pro/news/zammad-cve-2026-102489-ai-agent-gets-root-patch-now.jsonld"}}