Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 8 min read

Two Zammad Zero-Days: DIVD Reports Session Compromise, Root Access, and Data Theft

1. Overview Article Title: When hackers get hacked, we deal with it in hacker style. Publisher: DIVD Publication Date: 2026-09-30 Source: DIVD Related References: DIVD: Zammad vulnerability case, DIVD: incident

1. Overview

  • Article Title: When hackers get hacked, we deal with it in hacker style.
  • Publisher: DIVD
  • Publication Date: 2026-09-30
  • Source: DIVD
  • Related References: DIVD: Zammad vulnerability case, DIVD: incident timeline, DIVD: initial incident statement, BleepingComputer, Zammad security advisories
  • Related Malware, Threat Groups, CVEs, Products: CVE-2026-102489, CVE-2026-102490, Zammad
  • Severity: Critical (DIVD reported session compromise, remote code execution, root access, and data exfiltration in its own environment, and assessed that an AI agent was involved.)

  • Reason for Update: Clarified the role of each CVE, the limitations of upgrading to version 7, the available IoC-checking tool, and the criteria for confirming compromise, based on DIVD's post and its October 1 case file update.

2. Executive Summary

DIVD reported a compromise of Zammad that chained CVE-2026-102489 for session hijacking and remote code execution with CVE-2026-102490 for local privilege escalation from the zammad user to root. DIVD assessed that an AI agent was involved and reported that the sequence through root access took seconds. It recommends upgrading to version 7 or taking the instance offline, but migration to version 7 should not be treated as a complete fix for both CVEs.

3. Attack Flow

Chaining Two Zero-Days to Gain Root Access and Exfiltrate Data

  1. According to DIVD, the attackers exploited CVE-2026-102489 against its externally reachable Zammad instance. DIVD identifies versions 6.3.0 through 6.5.4 as affected. It states that versions 7.0.0 through 7.1.3 also contain the issue but that environmental conditions prevent exploitation in those versions. Detailed attack requests have not been published.
  2. CVE-2026-102489 enabled session hijacking and remote code execution as the zammad user. The precise sequence of these operations cannot be established from the public materials alone.
  3. The attackers subsequently exploited CVE-2026-102490 to escalate from the local zammad user to root. DIVD reported that they then accessed other services.
  4. DIVD also reported data reading and exfiltration. Its description of activity occurring within seconds applies to session hijacking, remote code execution, and escalation to root. The total duration of the sequence, including data exfiltration, was not disclosed.
  5. DIVD stated that network segmentation and incident response prevented the attackers from moving deeper into its systems and network.

4. Attacker Position and Execution Environment

  • The attackers could reach DIVD's Zammad instance over the network. The reviewed DIVD materials do not specify whether exploiting CVE-2026-102489 requires prior authentication. Exploiting CVE-2026-102490 requires local privileges as the zammad user.
  • Code execution and privilege escalation occurred on the Zammad server. DIVD reported access to other services after the attackers obtained root privileges.

5. Victim and Administrator Visibility

Victims

  • Inference: Users might notice abnormal ticketing behavior or unexpected changes in their sessions. However, specific user-visible symptoms have not been publicly disclosed.

Administrators

  • Inference: Available logs may allow correlation among Zammad sessions, web requests, child processes, privilege escalation events, outbound connections, and connections to other services.
  • DIVD provides an IoC-checking script for Zammad logs through its case file.

6. Success and Failure Conditions

Success Conditions

  • The attackers must be able to reach a Zammad instance whose version and environment permit exploitation of CVE-2026-102489. DIVD describes versions 6.3.0 through 6.5.4 as exploitable and states that environmental conditions prevent exploitation in versions 7.0.0 through 7.1.3.
  • Exploitation of CVE-2026-102489 must result in session compromise and code execution as the zammad user.
  • Escalation to root requires exploitation of CVE-2026-102490 from local zammad user privileges. Subsequent compromise of other services and theft of their data also depend on the access paths and any credentials required by those services.

Failure Conditions and Risk Mitigation

  • Follow DIVD's recommendation to upgrade to version 7 or take the instance offline. Its statement that environmental conditions prevent exploitation of CVE-2026-102489 in version 7 does not establish that CVE-2026-102490 has been patched. Confirm the fixed versions and applicable conditions for the local privilege escalation vulnerability with the vendor.
  • Use network segmentation to separate the Zammad server from other services, and minimize service account privileges and reachable destinations.
  • Store web session, server, and network telemetry externally, and prepare automated containment procedures capable of responding within seconds.

7. What Happens Upon Success

  • DIVD reported session hijacking, remote code execution, and escalation to root.
  • DIVD reported access to other services, data reading, and data exfiltration.
  • Segmentation prevented movement deeper into the network, while the investigation remained ongoing.

8. Observable Logs

  • Email: If Zammad is configured to ingest email channels, check for ticket generation, attachments, and email processing around the time of the attack. It has not been publicly confirmed whether the initial request originated via email.
  • Proxy / SWG / DNS: Review logs from components in front of Zammad for HTTP requests, session cookie use, and responses. Also examine communications from the server to unknown domains.
  • Endpoint / EDR: Review child processes spawned by the Zammad process, shell activity, file writes, root privilege escalation, and credential access.
  • Identity / IdP: Investigate compromised sessions and logins to other services using accounts or tokens from the Zammad host.
  • SaaS / Cloud: Check access to and exports of tickets, attachments, API integrations, and backups.
  • Network: Monitor for connections from Zammad outside its segment, data transfers, and East-West traffic to other services, measured on a per-second basis.

9. Compromise Determination

Confirmed in Public Information

DIVD reported session hijacking, remote code execution, escalation to root, access to other services, and data exfiltration in its own environment. The case file describes the role of each CVE, but the reviewed materials do not establish the detailed attack requests or the full scope of exfiltrated data.

Criteria for Internal Assessment

  • Information Theft or Session Compromise Confirmed: Public information: DIVD reported session hijacking and data exfiltration in its environment. Assessment criteria: In your own environment, classify this stage as confirmed only when there is evidence of unauthorized session use or protected data reaching the attacker. Remote code execution or root access alone does not establish information theft, and outbound traffic alone does not prove successful exfiltration. Attack requests alone do not establish successful exploitation.

10. Investigation Playbook

  • Investigation Starting Point: Begin with affected versions, external exposure, abnormal Zammad sessions, and server process warnings.
  • Initial Verification: Check versions, patch status, exposure scope, sessions, web requests, processes, and outbound communications.
  • Endpoint and Server Investigation: Preserve memory, disk, processes, shell history, and sudo/audit logs on the Zammad host.
  • Authentication and Cloud Investigation: Revoke tokens and sessions associated with Zammad and connected services, rotate service account credentials, and issue replacement tokens as needed.
  • Tracing Subsequent Actions: Track logins to other services, data reads, archive creation, and exfiltration traffic.
  • Containment: Isolate the instance or take it offline, preserve evidence, and proceed with DIVD's recommended migration to version 7 and investigation of the compromise. Do not assume that updating alone removes an existing compromise or resolves the local privilege escalation vulnerability; verify the fix status. Block unauthorized traffic from the affected host to other segments.
  • Categorization: Record attack requests, session hijacking, RCE, root privilege escalation, access to other services, and data exfiltration separately.

11. Defense and Detection Ideas

  • Single Events: Prioritize shell execution from the Zammad process, root escalation, and outbound connections to unknown destinations.
  • Timeline Correlation: Correlate session anomalies -> child process creation -> root escalation -> access to other services -> data transfer on a per-second timescale.
  • Threat Hunting: Search for connections from the Zammad host to internal services and external destinations that are not normally utilized.
  • Log Limitations: DIVD provides an IoC-checking script, but WAF logs or the absence of IoC matches alone cannot rule out a past compromise. Assess logging coverage and retention alongside session, host, and network evidence.
  • Priority Mitigations: Prioritize migration to version 7 or taking the instance offline as recommended by DIVD, investigation of existing compromise, verification of the local privilege escalation fix, network segmentation, least privilege for service accounts, and external log storage.

12. Facts / Inference / Hypothesis

Facts

  • DIVD confirmed a compromise chaining two Zammad zero-days, assigning identifiers CVE-2026-102489 and CVE-2026-102490.
  • DIVD stated that session hijacking, remote code execution, and escalation from the zammad user to root progressed within seconds, followed by access to other services and data reading and exfiltration. The involvement of an AI agent represents DIVD's assessment.
  • DIVD stated that network segmentation and incident response prevented attackers from moving deeper into the network.
  • DIVD recommends upgrading to version 7 or stopping the service. Its case file describes CVE-2026-102489 as exploitable in versions 6.3.0 through 6.5.4 and present but not exploitable due to environmental conditions in versions 7.0.0 through 7.1.3. CVE-2026-102490 enables local escalation from the zammad user to root; the case file's narrative describes all versions, including the latest alpha, as affected.

Inference

  • DIVD assessed that an AI agent was involved based on how the attack was carried out. That assessment alone does not establish that the entire operation, from preparation before intrusion to subsequent actions, was autonomous or that no human supervision was involved.

Hypothesis

No additional hypotheses. Unconfirmed items are noted in section 14, Unresolved Questions and Further Investigation.

13. MITRE ATT&CK Mapping

ID Technique Confidence Basis
T1190 Exploit Public-Facing Application high Proceeded to session hijacking and RCE via a zero-day chain against externally reachable Zammad instances.
T1068 Exploitation for Privilege Escalation medium DIVD states CVE-2026-102490 escalates privileges from the local zammad user to root; detailed exploitation steps are unpublished.

14. Unresolved Questions and Further Investigation

  • The detailed root causes, attack requests, and fix commits for each CVE. For CVE-2026-102490, DIVD's narrative describes all versions as affected, while its table lists v1.5.0 through v7.1.0-alpha. The case file also displays β€œPatch status: Available” while stating that the vendor is working on a fix. The exact fixed versions and applicable conditions, including those for version 7, therefore require confirmation.
  • The full scope of exfiltrated data, credentials used for other services, and the threat actor identity. While DIVD's incident timeline references follow-up reports on victim data from October 1, the specific text has not been reviewed here.
  • The AI agent's model, tool permissions, human involvement, and pre-intrusion preparation.

15. Impact on SOCs and Organizations

Because help desks consolidate tickets, attachments, user information, API tokens, and internal communications, a compromise of Zammad extends far beyond a mere support system outage. Prioritize version verification and isolation, and examine web sessions, Zammad processes, root privilege acquisition, outbound transmissions, and authentication to other services across a unified timeline. Anticipate AI-driven acceleration and automate or pre-approve containment procedures under the assumption that delay between alerts and manual approval equates to expanded breach scope.

16. Target Audience Summary

  • For SOCs: Correlate Zammad sessions, web requests, process and sudo records, outbound communications, and logins to other services on a per-second basis.
  • For Administrators: Follow DIVD's recommendation to migrate to version 7 or take the instance offline, and preserve evidence. Do not assume that migration alone fixes both CVEs; verify the local privilege escalation fix and investigate any existing compromise.
  • For Users: Promptly comply if administrators request verification of information handled via Zammad or credential updates.
πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.