PT-2026-99077 · Zammad · Zammad
CVE-2026-61855
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Zammad versions 7.0.3 and 7.1.1
Description
Zammad is a web-based open source helpdesk and customer support system. The software incorrectly verifies inbound PGP-signed emails under certain conditions, marking messages as having a valid PGP signature from a registered sender key even when the displayed content is not covered by that signature. This results in inbound articles being stored with a successful signature status that does not reflect the actual authenticity of the content, potentially misleading agents who rely on the signature indicator to assess the trustworthiness of incoming mail.
Recommendations
Update Zammad versions 7.0.3 and 7.1.1 to version 7.1.2.
Exploit
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zammad