SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-47255

HIGH · CVSS 8.2 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The AgenticMail API and core components prior to versions 0.9.32 and 0.9.10, respectively, are vulnerable due to multiple weaknesses in validation processes, SQL identifier handling, and TLS certificate verification. Exploitation of these vulnerabilities could lead to unauthorized access to sensitive email and phone data, potentially compromising user privacy and security. Organizations using these versions should prioritize upgrading to the patched releases to mitigate the risk of data breaches and ensure secure communications.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-47255
Severity
HIGH
CVSS
8.2
EPSS
0.18%

Original NVD Description

AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage SQL identifier validation; metadata-backed ownership checks for raw storage SQL; blocking direct storage metadata access through raw SQL; fail-closed outbound worker secret handling; SMTP envelope/header control-character validation before command construction; and TLS certificate verification as the default for MailSender with an explicit opt-out for local development. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 are patched.