PT-2026-99090 · Zammad · Zammad
CVE-2026-84465
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Zammad versions prior to 7.1.2
Description
Zammad fails to properly verify the trust of signing certificates when processing incoming S/MIME-signed emails. Instead of validating the certificate chain, the system only checks if a certificate with a matching name exists in its storage. This allows an attacker to forge emails by creating a self-signed certificate using the name of a previously trusted sender. Consequently, the system marks these forged messages as validly signed, misleading users into believing the email originated from a trusted source.
Recommendations
Update to version 7.1.2.
Exploit
Fix
Authentication Bypass by Spoofing
Improper Certificate Validation
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zammad