PT-2026-99077 · Zammad · Zammad

CVE-2026-61855

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Zammad versions 7.0.3 and 7.1.1
Description Zammad is a web-based open source helpdesk and customer support system. The software incorrectly verifies inbound PGP-signed emails under certain conditions, marking messages as having a valid PGP signature from a registered sender key even when the displayed content is not covered by that signature. This results in inbound articles being stored with a successful signature status that does not reflect the actual authenticity of the content, potentially misleading agents who rely on the signature indicator to assess the trustworthiness of incoming mail.
Recommendations Update Zammad versions 7.0.3 and 7.1.1 to version 7.1.2.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61855
GHSA-R957-VP26-563Q

Affected Products

Zammad