A vulnerability categorized as critical has been discovered in AgenticMail. The impacted element is the function GET /api/agenticmail/tasks/pending of the file /api/agenticmail/tasks/pending of the component Task Management. Executing a manipulation of the argument assignee can lead to authorization bypass.

The identification of this vulnerability is CVE-2026-57494. The attack may be launched remotely. There is no exploit available.