A vulnerability was found in agenticmail claudecode, codex, core and openclaw and classified as critical. This vulnerability affects unknown code of the component Mail Handler. The manipulation of the argument from/subject/preview results in permission issues.
This vulnerability is known as CVE-2026-57495. It is possible to launch the attack remotely. No exploit is available.