Resources
/
Blog
Podcast
Video

Kill Chains and Coffee Episode 7: Zero-Day Exploits to Active Directory Access

30 Sep 2026
WRITTEN BY
Nick McClendon
Kill Chains and Coffee Episode 7: Zero-Day Exploits to Active Directory Access
Contents

Key Takeaways

  • Armadin identified two vulnerabilities and went from an unauthenticated user to command execution on an enterprise cloud backup solution. 
  • The vulnerabilities have not yet been assigned CVEs. The affected vendor has been notified, the vulnerabilities have been patched, and the vendor has notified impacted customers.
  • Armadin tested all customer environments running the software against this chain and notified any that were affected, ahead of this public disclosure.
  • Armadin plans to publish full technical details of the vulnerabilities after CVEs have been assigned.

Overview: RCE through Chained Vulnerabilities

Armadin obtained remote code execution (RCE) on an enterprise cloud backup solution through a chain of vulnerabilities requiring only network access to the application. 

Externally accessible cloud backup solutions are enticing targets for attackers. They often run with high privileges, have access to sensitive data and environments, and expose a wealth of functionality that could be abused through an authentication bypass.

Armadin’s work started with reverse engineering of the application, initially focused on expanding the attack surface past an unauthenticated user. After identifying an authentication bypass, Armadin focused on functionality that could provide internal network access to a privileged user.

The full RCE chain followed:

  1. An authentication bypass that allowed self-registration of a privileged user account.
  2. An unrestricted file upload vulnerability that allowed uploaded files to be written to the web root of the application, enabling command execution.

Authentication Bypass

Armadin focuses heavily on authentication bypasses when attacking externally accessible applications. An application’s unauthenticated footprint is usually small, while the expanded functionality of a privileged user often leads to high-impact vulnerabilities. In this case, the authentication bypass vulnerability expanded access into local file management functionality.
‍
Kill chains that include an initial vulnerability that expands the accessible functionality have become a common pattern for external web application compromise. Vulnerabilities that increase application access, like authentication bypasses and server-side request forgery (SSRF), can turn a relatively small external attack surface into a much larger one.

Command Execution

The application, like most cloud backup products, contained extensive local file management functionality by design. One such feature allowed a privileged user to create new directories to store file uploads for incoming backups but did not validate that the selected directory was the application’s web root.

Armadin leveraged this issue, along with the ability to upload arbitrary files, to upload a web shell into the web root, granting command execution as NT AUTHORITY\SYSTEM on the cloud backup server.

This combination has become increasingly common in the kill chains Armadin has found. Externally accessible applications expose sensitive functionality by design to privileged users. A vulnerability that provides access to those privileges can quickly turn intended administrative functionality into a path to application compromise.

Defensive Considerations

Even in the age of machine-speed AI attacks, good security hygiene limits the impact of a compromised application.

Armadin recommends limiting the exposure of management interfaces to the public Internet through a combination of virtual private networks (VPNs), IP address allowlisting, and zero-trust network access (ZTNA) solutions.

In instances where applications must be externally exposed, they should have limited access to sensitive internal network systems. Exposed applications should live within a DMZ, cordoned off from other networks to limit the impact of compromise.

Acknowledgements

Special thanks to Nick Cerne for his discovery of these vulnerabilities.

Dive Deeper

Discover how a safe Hyperattack assessment from Armadin gives you the tools and confidence to identify exploitable risk across your environment. Learn more about Hyperattacks.

Continue reading
Safe Autonomous Security: Armadin Joins NVIDIA Agent Safety Platform
News
9.28.26
Safe Autonomous Security: Armadin Joins NVIDIA Agent Safety Platform
Kill Chains and Coffee Episode 5: Why AI Beats Human Pentesting
Blog
Podcast
Video
9.3.26
Kill Chains and Coffee Episode 5: Why AI Beats Human Pentesting
Compromising Cleo Harmony: A SAML Bypass Chain to Arbitrary Code Execution
Blog
9.2.26
Compromising Cleo Harmony: A SAML Bypass Chain to Arbitrary Code Execution