CVE-2026-84462: Zammad: AI Agent template sanitizer bypass leads to remote code execution
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zammad's AI Agent configuration can be bypassed by entering specially crafted text into one of an AI Agent's fields. An administrator with permission to create or edit AI Agents could exploit this to run arbitrary commands on the server that hosts Zammad, potentially reading, modifying, or destroying all data stored on that server. No interaction from other users is needed; the malicious code runs automatically the next time the affected AI Agent processes a ticket. This issue is fixed in version 7.1.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zammadto a version that resolves this vulnerability.Fixed in 7.1.2
Event History
Frequently Asked Questions
Who can exploit this issue?
An administrator who has permission to create or edit AI Agents can exploit it. Exploitation requires entering specially crafted text into an AI Agent field.
When does the malicious code execute?
The code runs automatically the next time the affected AI Agent processes a ticket. No interaction from other users is required.
What systems are affected?
Zammad versions prior to 7.1.2 are affected. The issue is fixed in version 7.1.2.
What is the potential impact of successful exploitation?
An attacker can run arbitrary commands on the server hosting Zammad. This could allow them to read, modify, or destroy all data stored on that server.