ATLAS Landscape
AML.T0081

Modify AI Agent Configuration

Adversaries may modify the configuration files for AI agents on a system. This allows malicious changes to persist beyond the life of a single agent and affects any agents that share the configuration. Configuration changes may include modifications to the system prompt, tampering with or replacing knowledge sources, modification to settings of connected tools, and more. Through those changes, an attacker could redirect outputs or tools to malicious services, embed covert instructions that exfiltrate data, or weaken security controls that normally restrict agent behavior. Adversaries may modify or disable a configuration setting related to security controls, such as those that would prevent the AI Agent from taking actions that may be harmful to the user's system without human-in-the-loop oversight. Disabling AI agent security features may allow adversaries to achieve their malicious goals and maintain long-term corruption of the AI agent.

Severity CVE CVSS
CRITICAL GHSA-wpqr-6v78-jr5g 10.0
CRITICAL CVE-2026-40933 9.9
CRITICAL CVE-2026-25049 9.9
CRITICAL CVE-2026-33309 9.9
CRITICAL CVE-2026-27577 9.9
CRITICAL CVE-2026-27495 9.9
CRITICAL CVE-2026-21877 9.9
CRITICAL CVE-2026-1470 9.9
CRITICAL CVE-2026-27494 9.9
CRITICAL CVE-2026-27966 9.8
CRITICAL CVE-2025-61260 9.8
CRITICAL CVE-2026-41276 9.8
CRITICAL CVE-2026-41268 9.8
CRITICAL CVE-2026-35022 9.8
CRITICAL CVE-2026-39890 9.8
CRITICAL CVE-2025-13374 9.8
CRITICAL GHSA-2763-cj5r-c79m 9.7
CRITICAL CVE-2026-27493 9.0
CRITICAL CVE-2026-33749 9.0
HIGH CVE-2026-33696 8.8
HIGH CVE-2026-27497 8.8
HIGH CVE-2025-68613 8.8
HIGH CVE-2024-6825 8.8
HIGH CVE-2026-41269 8.8
HIGH CVE-2023-27563 8.8
HIGH CVE-2026-27498 8.8
HIGH CVE-2026-25056 8.8
HIGH CVE-2025-56265 8.8
HIGH GHSA-cwj3-vqpp-pmxr 8.8
HIGH CVE-2025-65964 8.8
HIGH CVE-2026-41277 8.8
HIGH CVE-2026-44552 8.7
HIGH CVE-2026-30617 8.6
HIGH CVE-2026-40113 8.4
HIGH CVE-2026-33665 8.2
HIGH CVE-2026-25055 8.1
HIGH CVE-2024-7806 8.0
HIGH CVE-2026-40149 7.9
HIGH GHSA-cvrr-qhgw-2mm6 7.7
HIGH CVE-2026-21852 7.5
HIGH CVE-2026-33724 7.4
HIGH CVE-2025-30167 7.3
HIGH CVE-2026-21893 7.2
HIGH CVE-2025-5018 7.1
HIGH GHSA-rh7v-6w34-w2rr 7.1
HIGH CVE-2025-68478 7.1
MEDIUM CVE-2026-26972 6.7
MEDIUM CVE-2026-4502 6.5
MEDIUM CVE-2026-44562 6.5
MEDIUM CVE-2026-6599 6.3
MEDIUM CVE-2025-46343 5.4
MEDIUM CVE-2025-61914 5.4
MEDIUM GHSA-364x-8g5j-x2pr 5.4
MEDIUM CVE-2026-25054 5.4
MEDIUM CVE-2026-25051 5.4
MEDIUM CVE-2026-27578 5.4
MEDIUM CVE-2024-4858 5.3
MEDIUM CVE-2025-54558 4.1
CRITICAL GHSA-xh72-v6v9-mwhc
UNKNOWN CVE-2025-55012
UNKNOWN CVE-2026-34046
MEDIUM CVE-2026-34450
UNKNOWN CVE-2026-35029
UNKNOWN CVE-2026-30823
UNKNOWN CVE-2026-30822
MEDIUM GHSA-98ch-45wp-ch47
MEDIUM GHSA-2qrv-rc5x-2g2h
MEDIUM GHSA-m34q-h93w-vg5x
MEDIUM GHSA-42mx-vp8m-j7qh
LOW GHSA-767m-xrhc-fxm7
MEDIUM GHSA-3q42-xmxv-9vfr
HIGH GHSA-vfw7-6rhc-6xxg
LOW GHSA-4f8g-77mw-3rxc
MEDIUM GHSA-67mf-f936-ppxf
HIGH GHSA-5wj5-87vq-39xm
MEDIUM GHSA-vc32-h5mq-453v
MEDIUM GHSA-68x5-xx89-w9mm
MEDIUM GHSA-cmfr-9m2r-xwhq
CRITICAL CVE-2026-40111
LOW GHSA-cm8v-2vh9-cxf3
MEDIUM GHSA-x783-xp3g-mqhp
HIGH GHSA-r6xh-pqhr-v4xh
MEDIUM GHSA-55cf-xx38-4p9p
MEDIUM GHSA-q3jj-46pq-826r
UNKNOWN CVE-2026-41686
MEDIUM GHSA-c28g-vh7m-fm7v
UNKNOWN CVE-2026-42231
UNKNOWN CVE-2026-42235
MEDIUM GHSA-7jm2-g593-4qrc
MEDIUM GHSA-h2vw-ph2c-jvwf
MEDIUM GHSA-mj59-h3q9-ghfh
MEDIUM GHSA-hxvm-xjvf-93f3
LOW GHSA-xrq9-jm7v-g9h7
MEDIUM GHSA-2xcp-x87w-q377
HIGH CVE-2026-40068