PT-2026-99090 · Zammad · Zammad

CVE-2026-84465

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.1.2
Description Zammad fails to properly verify the trust of signing certificates when processing incoming S/MIME-signed emails. Instead of validating the certificate chain, the system only checks if a certificate with a matching name exists in its storage. This allows an attacker to forge emails by creating a self-signed certificate using the name of a previously trusted sender. Consequently, the system marks these forged messages as validly signed, misleading users into believing the email originated from a trusted source.
Recommendations Update to version 7.1.2.

Exploit

Fix

Authentication Bypass by Spoofing

Improper Certificate Validation

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84465
GHSA-M9FF-HJR3-93H4

Affected Products

Zammad