Threat · curated 26 Sep 2026
CVE Record: CVE-2026-84462
First reported cve.org
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
CVE-2026-84462 shows that sanitizers guarding AI Agent configuration surfaces can be bypassed to achieve full remote code execution, turning an AI-agent feature into a server compromise vector.
CVE-2026-84462 is a vulnerability in Zammad, an open-source helpdesk system, where a security filter protecting the AI Agent configuration can be bypassed by entering specially crafted input, leading to remote code execution. The flaw (CWE-94/CWE-1336 template injection) affects versions prior to 7.1.2 and is fixed in that release.