CVE-2026-84462
Received Received - Intake

Remote Code Execution in Zammad AI Agent

Vulnerability report for CVE-2026-84462, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: GitHub, Inc.

Description

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zammad's AI Agent configuration can be bypassed by entering specially crafted text into one of an AI Agent's fields. An administrator with permission to create or edit AI Agents could exploit this to run arbitrary commands on the server that hosts Zammad, potentially reading, modifying, or destroying all data stored on that server. No interaction from other users is needed; the malicious code runs automatically the next time the affected AI Agent processes a ticket. This issue is fixed in version 7.1.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-26
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zammad zammad 7.1.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1336 The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Zammad is a helpdesk system. A flaw in versions before 7.1.2 allows an administrator to bypass security filters in AI Agent configuration fields. By entering crafted text, they can execute arbitrary commands on the server hosting Zammad. This could lead to unauthorized access, data theft, modification, or deletion. The exploit runs automatically when the AI Agent processes a ticket.

Detection Guidance

This vulnerability can be detected by checking the Zammad version installed on your system. If the version is below 7.1.2, the system is vulnerable. Run the command: zammad version to check the installed version. Additionally, review AI Agent configurations for any suspicious or unexpected commands in their fields.

Impact Analysis

If you are an administrator with permission to create or edit AI Agents in Zammad versions before 7.1.2, an attacker could exploit this to gain full control over your server. This includes reading, modifying, or deleting all data stored in Zammad. Even if you are not an administrator, your data could be at risk if an administrator's account is compromised.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR's data protection requirements and HIPAA's security rules. Organizations using affected Zammad versions may face compliance violations, legal penalties, and reputational damage if sensitive data is exposed or altered.

Mitigation Strategies

Upgrade Zammad to version 7.1.2 or later immediately to patch the vulnerability. Review AI Agent configurations for suspicious entries and restrict administrative permissions to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84462. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart