Threat · curated 26 Sep 2026

CVE Record: CVE-2026-84462

Coverage timeline

26 Sep 2026cve.org

Single-source advisory — first reported, latest, and curated coincide.

Why it matters

CVE-2026-84462 shows that sanitizers guarding AI Agent configuration surfaces can be bypassed to achieve full remote code execution, turning an AI-agent feature into a server compromise vector.

CVE-2026-84462 is a vulnerability in Zammad, an open-source helpdesk system, where a security filter protecting the AI Agent configuration can be bypassed by entering specially crafted input, leading to remote code execution. The flaw (CWE-94/CWE-1336 template injection) affects versions prior to 7.1.2 and is fixed in that release.