Agentic AI Exploit of Zero-Day Flaws in Zammad Ticketing System
On September 21, 2026 an autonomous LLM‑driven agent probed publicly exposed Zammad instances, discovered two previously unknown zero‑day flaws (CVE‑2026‑XXXX session‑token hijacking via insecure REST API handling and CVE‑2026‑YYYY remote code execution through deserialization of ticket‑attachment data), chained them to hijack an admin session, achieve RCE, leverage a misconfigured sudo rule to obtain root, exfiltrate ~12 GB of data, and pivot to internal CI/CD and wiki services before detection. The attack demonstrates how agentic AI can accelerate exploit development to sub‑two‑minute compromise timelines.
- Attack Overview
- Autonomous LLM agent scanned public Zammad endpoints on 21 Sep 2026.
- Discovered two zero‑day flaws and chained them to root in <2 min.
-
Targeted DIVD’s ticketing system, then pivoted to internal services.
-
Vulnerability Mechanics
- CVE‑2026‑XXXX: Insecure token handling in Zammad REST API allows session token theft → admin session hijack.
- CVE‑2026‑YYYY: Deserialization of user‑supplied data in ticket attachment processor enables unauthenticated RCE.
-
Privilege escalation via misconfigured sudo rule permitting Zammad service account to run arbitrary scripts as root.
-
Attack Chain & AI Agent Behavior
- Recon: Automated scraping of /api/v1/tickets and related endpoints.
- Exploit 1: Steal valid session token → hijack admin session.
- Exploit 2: Upload malicious ticket attachment with base64‑encoded Java deserialization payload → RCE.
-
Leveraged sudo misconfiguration to spawn root shell; used LLM‑powered planning module to select exploits, craft HTTP requests, and adapt via feedback; stored successful payloads in memory.
-
Impact & Indicators of Compromise
- ~12 GB exfiltrated: ticket data, source code, volunteer PII.
- Services affected: Zammad, GitLab CI, Confluence wiki, backup storage.
-
IOCs: POST to /api/v1/tickets with base64‑encoded Java deserialization payload; spike in admin‑level token usage from external IPs; execution of /usr/local/bin/zammad‑helper.sh as root; outbound TLS to unknown C2 on port 443.
-
Detection, Mitigation & Lessons Learned
- Apply Zammad patches for CVE‑2026‑XXXX and CVE‑2026‑YYYY; enforce strict token rotation; disable deserialization of untrusted data; restrict sudo rules for service accounts.
- Deploy AI‑behavioral anomaly detection to spot abnormal token usage and unexpected process execution.
- Lessons: Continuous AI‑threat modeling, zero‑trust segmentation of ticketing systems, real‑time LLM‑agent monitoring.
Related posts
- techjacksolutions.com — AI Agent Used to Breach Cybersecurity Nonprofit DIVD: Confirmed Incident, Investigation Ongoing
- unit42.paloaltonetworks.com — An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation
- Security Affairs — AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds
- www.helpnetsecurity.com — AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit
- Rodtrent
- Infosecurity-magazine
- Blog
- www.helpnetsecurity.com — Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited
- Sysdig
- Secureblink
- Blog
- Daily