ACVEAgent configuration vulnerability registry

ACVE-2026-0538

An AI agent used by an attacker logged in to an organisation's application, modified personal data and accessed invoices, in the first such breach notified to Spain's data regulator.

Exposure

Reproducibility: partial (model availability not checked (no registry reference); trigger not published)

Claims

Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.

The exposure axes marked confirmed were matched to the first-hand sources listed above.

Description

Threat

user · unsafe-default · harmful-action

What

Spain's data-protection regulator, the AEPD, published the first breach notification it has received for an attack carried out through an AI agent that used a well-known language model, which it does not name. According to the affected organisation's notification, a third party used the agent as an instrument to chain the phases of the attack: it searched generic files for vulnerabilities and logged in successfully, then autonomously searched the application for vulnerabilities, which let it modify personal data and access invoices. The AEPD does not name the organisation, does not say how the login was obtained or whether the data was restored, and cautions that using a specific model does not imply the model or its provider was compromised.

Detection

The AEPD says the information comes from the organisation's notification and still has to be analysed. Recorded from the AEPD's post. Not recreated in a lab.

Fix

Protect credentials and digital identities, add rapid detection and containment, and keep high-impact actions under human control.

Fix

The attacker ran the agent, so the controls that protect victims are the targeted organisation's credential protection and fast detection, and the model provider's misuse detection.

  • Reconfigure model-provider.misuseDetection to detects agents attacking third-party applications. Recommended: the attacker chained login, vulnerability search and data changes through one agent. Owner: model-provider
  • Reconfigure application.login to strong credential and identity protection. The targeted organisation's application accepted the agent's login; the AEPD recommends protecting credentials. Owner: operator
  • Reconfigure application.monitoring to fast detection and containment of automated attacks. The agent searched the targeted organisation's application on its own; the AEPD recommends fast detection and containment. Owner: operator

References

ARTICLE

Report a problemJSON