DEV Community

yutianle
yutianle

Posted on

When an Agent Reaches Root: The Zammad Attack and Machine-Speed Intrusion

When an Agent Reaches Root: The Zammad Attack and Machine-Speed Intrusion

Vulnerability overview

The Zammad compromise at DIVD is memorable for two reasons. Technically it is a two-stage chain: CVE-2026-102489 for session hijacking and remote code execution as the zammad user, CVE-2026-102490 for escalation to root. Operationally, DIVD says the intrusion "indicates an agentic AI powered attack, something we had not seen before."

Mechanism and exploitation conditions

The mechanics are conventional enough. CVE-2026-102489 requires no privileges and only some passive user interaction, scoring 8.7 standalone on CVSS 4.0. CVE-2026-102490 needs local access, scoring 8.5 alone, and completes the path to root. Both records rate the chain 9.4, Critical, and mark it automatable — a label that fits the observed behaviour.
What stood out to investigators was the script's internal commentary. Log files showed the attacker's scripts carried notes in which the agent justified its own actions, something DIVD argues a human attacker "wouldn't bother with." The activity was fast but messy: DIVD describes an agent "deciding each next step itself at speed on sloppy logic." Those overexplaining notes later made reverse engineering easier, and DIVD found no link to any known threat actor.

Impact

The outcome was still severe. Attackers took volunteer data, including DIVD email addresses and possibly contact details, and DIVD warns this makes it easier for someone to pose as a volunteer. Network segmentation limited the damage. For defenders the practical lesson is that speed of exploitation is no longer bounded by a human operator's typing, so dwell time assumptions need revision.

Affected products and scope

CVE-2026-102489 is exploitable on Zammad 6.3.0 through 6.5.4; versions 7.0.0 to 7.1.3 contain the defect but are assessed as not exploitable due to environment conditions. CVE-2026-102490 covers Zammad 1.5.0 to the 7.1.0 alpha. Linux and Docker deployments are affected.

Exposure context

At collection time, app="Zammad" matched 11,977 instances on ZoomEye (2026-10-02T06:12:32Z). This measures fingerprint exposure, not confirmed vulnerable systems; a vul.cve query for CVE-2026-102490 returned zero results. Machine-speed exploitation raises the value of knowing which instances are reachable before an incident begins.

Remediation and mitigations

Upgrade to Zammad version 7 or take the service offline to remove the remote stage. The escalation bug remains in current releases pending a vendor fix. Additional steps recommended by DIVD: run the published log check script, cut direct internet access or require VPN, rotate credentials stored on or reachable from the server, and segment the helpdesk from other critical systems. Assume compromise for instances that were exposed before patching.

References

Top comments (0)