Email Service Vulnerability in AgenticMail by Agentic
CVE-2026-47255

8.2HIGH

Key Information:

Vendor
CVE Published:
20 July 2026

What is CVE-2026-47255?

The AgenticMail service, utilized for managing AI agents' email communications, exhibits multiple vulnerabilities related to input validation and security filtering. Affected components, specifically @agenticmail/api and @agenticmail/core, fail to validate SQL identifiers properly, allowing potential unauthorized access to sensitive data. Additional concerns include improper handling of SMTP commands and inadequate verification of TLS certificates, posing threats to email safety. It is crucial to update to the latest versions to mitigate these risks and ensure robust security for communications.

Affected Version(s)

@agenticmail/api < 0.9.32

@agenticmail/core < 0.9.10

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.