PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-84462 zammad CVE debrief

CVE-2026-84462 is a high-severity vulnerability in Zammad, an open-source helpdesk/customer support system. An administrator with permission to create or edit AI Agents could exploit this vulnerability to run arbitrary commands on the server hosting Zammad, potentially reading, modifying, or destroying all data stored on that server. The issue is fixed in version 7.1.2.

Vendor
zammad
Product
Unknown
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Administrators with permission to create or edit AI Agents in Zammad, as well as defenders responsible for monitoring and securing Zammad instances, should be aware of this vulnerability and take steps to mitigate it.

Why it matters

CVE-2026-84462 is a high-severity vulnerability in Zammad that could allow administrators to run arbitrary commands on the server, potentially leading to data compromise or destruction. Defenders should prioritize patching and monitoring Zammad instances, especially if administrators have permission to create or edit AI Agents.

  • Potential for arbitrary command execution on the server hosting Zammad
  • Possible reading, modifying, or destruction of all data stored on the server
  • Need for verification of affected systems and administrator permissions
  • Priority for patching Zammad instances to version 7.1.2 or later

Technical summary

A security filter in Zammad's AI Agent configuration can be bypassed by entering specially crafted text into one of an AI Agent's fields, potentially allowing an administrator to run arbitrary commands on the server hosting Zammad. This could lead to reading, modifying, or destroying all data stored on that server. The issue is fixed in version 7.1.2. An administrator with permission to create or edit AI Agents could exploit this vulnerability. The malicious code runs automatically the next time the affected AI Agent processes a ticket, with no interaction from other users needed.

Defensive priority

Defenders should prioritize patching Zammad instances to version 7.1.2 or later, especially if administrators have permission to create or edit AI Agents.

Recommended defensive actions

  • Patch Zammad instances to version 7.1.2 or later
  • Restrict permissions for creating or editing AI Agents to trusted administrators
  • Monitor Zammad instances for suspicious activity
  • Review system logs for AI Agent processing anomalies
  • Verify affected systems and administrator permissions
  • Prioritize patching Zammad instances
  • Conduct a thorough review of AI Agent configurations

Evidence notes

The CVE record and NVD entry provide details about the vulnerability, its impact, and the fixed version. However, additional information about potential exploitation or affected systems is limited. Defenders should verify Zammad instances, especially if administrators have permission to create or edit AI Agents, and review system logs for suspicious activity related to AI Agent processing. The security filter bypass allows administrators to potentially run arbitrary commands, which could lead to data compromise or destruction. Limited

Sources and references

Verified primary and authoritative sources

  • CVE-2026-84462 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-84462

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-84462 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84462

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.