Breakglass
Incidents
← IncidentsConnecting…
INC-0008·Mercy Valley Community Hospital·Patient help deskReplay of a real KEV entrySimulated hospital

Zammad GmbH Zammad flaw on the patient help desk: contained without taking patient routes offline

CVE-2026-102489, Zammad GmbH Zammad (CISA KEV). The fixed version can't be installed today. Breakglass proves the flaw matters here, applies one reversible control, and proves patients can still book.

✓ CONTAINED
0:33
exposure closed, from ingest to verified
federal due window: 3 days

fig. 1 Evidence · two factors before any action

Could it happen here? Is it happening?
✓The code reaches the flawed partSemgrep · SEMGREP CE · config
targets/edge-config/nginx.conf:15 Reverse-proxy location `/support/api/v1/signshow` is open to the whole internet (allow all) and proxied to `http://zammad:3000`.
location /support/api/v1/signshow {
        allow all;
        proxy_pass http://zammad:3000;
rule bg-edge-location-allow-all
Third-party product with no source in scope: Semgrep checks the reverse-proxy config for internet exposure of the affected path.
✓That route is being hit right nowClickHouse · CLICKHOUSE CLOUD
20 requests to /support/api/v1/signshow in the last 5 min, 20 unblocked · 20 marker
ClickHouse decision: /support/api/v1/signshow · 20 requests in 5 min, 20 unblocked, hostile traffic on this route → exposed route → BG-CTL-SUPPORT-DISABLE-SESSION-API
The agent's query
SELECT route_id, client_kind, count() AS total, countIf(blocked = 0) AS unblocked
FROM bg.edge_requests
WHERE site = 'managed' AND route_id IN ('support.session')
  AND ts >= now() - INTERVAL 300 SECOND
GROUP BY route_id, client_kind
✓ BOTH FACTORS: MAY ACTStatic evidence alone, or traffic alone, never triggers a change.

fig. 3 Decision · one control ID from the catalog

guild:code~breakglass-decision · structured output
BG-CTL-SUPPORT-DISABLE-SESSION-API
Turn off the help desk's session sign-in API
  • Semgrep shows the affected /support/api/v1/signshow (support.session) is exposed in the edge proxy config.
  • ClickHouse confirms live hostile (non-patient marker) traffic: 20 requests recently to this endpoint, all unblocked.
  • The only eligible, low-blast reversible control (BG-CTL-SUPPORT-DISABLE-SESSION-API) covers the vulnerable sign-in API route.
  • Rejected alternatives: shutdown is not available via catalog and attachments control does not cover any exposed hostile route.
Considered and not chosen (2)
  • BG-CTL-SUPPORT-DISABLE-ATTACHMENTS Attachments control does not cover the exposed route.
  • BG-CTL-SUPPORT-SHUTDOWN Shutdown is not eligible via catalog and would impact critical routes.
reversiblefeature flagtouches no critical routepolicy: ALLOWconfidence 0.98

fig. 6 Controls applied

Every change, and every undo
ControlAppliedOutcome
BG-CTL-SUPPORT-DISABLE-SESSION-API04:29:03 UTCcontained
Exposure 0 and the patient journey passed.

fig. 4 Verification · risk down, care up

ClickHouse, per 10 s
probes that got through to /support/api/v1/signshow, per 10 s
1004:27:5004:29:20control applied0
patient journeys passing, % (one every 30 s; held between runs)
100004:27:5004:29:20control applied100%
Sign in✓ 100 ms
jordan.lee → /portal
Find a slot✓ 12 ms
8 slots listed
Book✓ 60 ms
Next-Action: book → 200
Confirm✓ 1 ms
Booked · MV-C0ZP
✓ EXPOSURE 0 UNBLOCKED / 20s✓ PATIENT JOURNEY · PLAYWRIGHT✓ CRITICAL ROUTES 0 × 5xx
fig. 5Agent trace · hosted and run in Guild 01a10a52-56d5-351a-0000-1c28731f482fopen in Guild ↗Guild's record →every tool call, logged
0100:00.0triggeradvisory.insert CVE-2026-102489 entered the advisory stream (REPLAY) → session started
0200:00.1toolinventory.match support · Zammad GmbH Zammad 6.4.1
0300:00.6triggerguild.session Guild session 01a10a52-56d5-351a-0000-1c28731f482f started for code~breakglass-decision
1300:03.8guildguild.llm model call · gpt-4.1 (openai)
1400:04.6guildguild.llm model asked for breakglass_incident_context, breakglass_inventory_match
1500:05.0guildguild.tool tool call (incident_id=INC-0008)
1600:05.1guildguild.tool tool call (incident_id=INC-0008)
1700:06.1guildguild.llm model call · gpt-4.1 (openai)
1800:06.8guildguild.llm model asked for breakglass_clickhouse_route_traffic, breakglass_semgrep_reachability
1900:07.1guildguild.tool tool call (incident_id=INC-0008)
2000:07.3guildguild.tool tool call (incident_id=INC-0008)
0400:07.5toolsemgrep.config reachable · 1 finding(s) · routes support.session
0500:08.0toolclickhouse.route_traffic 20 requests on 1 candidate route(s) in 5 min · hostile on support.session
2100:08.5guildguild.llm model call · gpt-4.1 (openai)
2200:09.6guildguild.llm model asked for breakglass_catalog_controls
2300:09.9guildguild.tool tool call (incident_id=INC-0008)
0600:10.3toolcatalog.list 1 of 3 controls eligible for support · ranker's first: BG-CTL-SUPPORT-DISABLE-SESSION-API
2400:10.8guildguild.llm model call · gpt-4.1 (openai)
2500:12.3guildguild.llm model asked for breakglass_submit_decision
2600:12.6guildguild.tool tool call (alternatives=[{'control_id': 'BG-CTL-SUPPORT-DISABLE-ATTACHMENTS', 'why_n, confidence=0.98, control_id=BG-CTL-SUPPORT-DISABLE-SESSION-API, incident_id=INC-0008, reasons=['Semgrep shows the affected /support/api/v1/signshow (suppo)
0700:13.1policygate.check ALLOWED BG-CTL-SUPPORT-DISABLE-SESSION-API: all checks passed
0800:13.2llmdecide guild:code~breakglass-decision → BG-CTL-SUPPORT-DISABLE-SESSION-API (confidence 0.98, 0 turns)
0900:13.4tooledge.apply BG-CTL-SUPPORT-DISABLE-SESSION-API → ALLOWED by credential policy (allow-apply-catalog)
2700:13.8guildguild.llm model call · gpt-4.1 (openai)
2800:14.8guildguild.reply BG-CTL-SUPPORT-DISABLE-SESSION-API
2900:15.1guildguild.done BG-CTL-SUPPORT-DISABLE-SESSION-API
1000:33.5verifyexposure 0 unblocked of 2 hostile requests in 20 s on support.session
1100:33.6verifyjourney Sign in ✓ → Find a slot ✓ → Book ✓ → Confirm ✓ (PLAYWRIGHT, 0.2 s)
1200:33.9statecontained exposure clock stopped at 0:33 · Turn off the help desk's session sign-in API · watch armed
Watch retiredAny unblocked non-patient request to /support/api/v1/signshow reopens INC-0008W-0008

fig. 7 Attack timeline · ClickHouse

UTC · from the request log and this incident's events

Peak 1 hostile requests per 10 s to /support/api/v1/signshow · 1 blocked after the control.

TimeWhat happenedSource
04:28:00 UTCFirst hostile request in the recorded window
1 non-patient request to /support/api/v1/signshow in that 10 s (the window starts 60 s before the incident opened)
ClickHouse
04:28:50 UTCAdvisory ingested
CVE-2026-102489 entered the advisory stream (replay of a real KEV entry)
MongoDB
04:28:58 UTCEvidence query
20 requests on 1 candidate route(s) in 5 min · hostile on support.session
ClickHouse
04:29:03 UTCControl applied
BG-CTL-SUPPORT-DISABLE-SESSION-API
edge
04:29:20 UTCFirst 10 s with nothing getting through
1 hostile request blocked, 0 through
ClickHouse
04:29:23 UTCVerified close
exposure 0 unblocked · patient journey passed · 0 × 5xx on critical routes
ClickHouse + Playwright

fig. 0 The advisory

What the government's list says
CVE-2026-102489Replay of a real KEV entry
Zammad GmbH Zammad Session Fixation Vulnerability

Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.

Added to KEV
Oct 2, 2026
Federal due date
Oct 5, 2026 (3 days after listing)
EPSS
1.4% chance of exploitation in 30 days · 71.5th percentile (2026-10-04)
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Timeline

UTC
Advisory ingested
04:28:50 UTC
Trigger
Replay of a real KEV entry into the advisory stream
Agent runtime
Hosted and run in Guild · Guild's record · strategy: containment-first
Opened
04:28:50 UTC
Closed
04:29:24 UTC

Mercy Valley is a fictional hospital; its portal is a harmless twin and the "attack" traffic is a benign marker request. What's live and what's simulated.