PT-2026-98941 · Zammad · Zammad
CVE-2026-56727
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Zammad versions prior to 7.0.2
Description
In the inbound PGP email processing, the return value of the gpg verification call is silently discarded. The handler unconditionally marks the security preferences of the article as having a successful signature with a "Good signature" comment, regardless of whether the signature is valid, invalid, or missing. This allows a sender to tamper with the body of a multipart/signed PGP email or craft a message with a fabricated or mismatched signature, which the system then displays as cryptographically verified. Consequently, users and agents may be misled into trusting modified or forged content.
Recommendations
Update to version 7.0.2.
As a temporary mitigation, disable the PGP integration to prevent the processing of signed emails.
Exploit
Fix
Improper Authentication
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zammad