The Dutch Institute for Vulnerability Disclosure (DIVD) says an autonomous AI agent chained two previously unknown Zammad vulnerabilities (CVE-2026-102489 and CVE-2026-102490) to breach its helpdesk systems and escalate to root access.
DIVD, which discovered the intrusion while investigating earlier suspicious activity, published a technical case showing the attack chain and working notes with its partner Merlon Security; the organization first announced it had been compromised in late September and then published the root-cause findings at the end of the month. The first flaw is described as an unauthenticated session‑hijack that can lead to remote code execution as the Zammad service user, while the second is a local privilege‑escalation that can turn any code‑execution foothold into full root on the host. Because the two bugs can be chained, DIVD and national authorities warn the combined scenario is far more severe than either bug alone; the Dutch NCSC published an advisory urging immediate mitigation and log preservation while fixes are applied.
DIVD said the incident unfolded in seconds and that investigators found artifacts suggesting agentic, autonomous behavior (an AI agent that adjusted actions and continued the exploit chain), though independent analysis and follow‑up is ongoing. Zammad users should follow DIVD’s guidance: apply the vendor’s patches where available, consider taking affected instances offline until mitigations are in place, and review logs and notifications for signs of abuse.