PT-2026-98958 · Zammad · Zammad

CVE-2026-84462

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.1.2
Description A security filter protecting the AI Agent configuration can be bypassed by entering specially crafted text into an AI Agent field. An administrator with permissions to create or edit AI Agents can exploit this to execute arbitrary commands on the host server, which may lead to the unauthorized reading, modification, or destruction of all stored data. The malicious code executes automatically when the affected AI Agent processes a ticket, requiring no interaction from other users.
Recommendations Update to version 7.1.2.

Exploit

Fix

Code Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84462
GHSA-GP3X-9XM8-RCJ6

Affected Products

Zammad