Zammad Zero-Day Chain Lets AI Agent Hijack Sessions, Execute Code and Escalate to Root
An AI agent breached the Dutch Institute for Vulnerability Disclosure by chaining two previously unknown flaws in Zammad, an open-source helpdesk platform. The September 21 attack moved from a hijacked session to root access, giving the intruder full server control within seconds. DIVD detected the intrusion the next day and blocked it.