CVE-2026-84462: Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zamm
criticalvulnerability
security
Summary
Zammad, a web-based customer support system, has a vulnerability in versions before 7.1.2 where a security filter protecting AI Agent configuration can be bypassed using specially crafted text. An administrator could exploit this to run arbitrary commands (code that executes whatever the attacker wants) on the server, potentially compromising all stored data.
Solution / Mitigation
Update Zammad to version 7.1.2 or later, which fixes this issue.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Disclosure Date
September 25, 2026
Classification
Attack SophisticationModerate
Impact (CIA+S)
integrityconfidentialityavailability
Affected Vendors
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-84462
First tracked: September 25, 2026 at 08:07 PM
Classified by LLM (prompt v3) · confidence: 92%