๐Ÿ” CVE Alert

CVE-2026-61855

UNKNOWN 0.0

Zammad: Invalid PGP Detached Signatures Reported as Good Signature on Inbound Mail

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, under certain conditions, Zammad's verification of inbound PGP-signed email can mark a message as carrying a valid ("Good") PGP signature from a registered sender key, even though the displayed message content is not actually covered by that signature. As a result, the inbound article may be stored with a successful signature status that does not reflect the authenticity of the shown content. This can mislead agents who rely on the signature indicator when assessing the trustworthiness of incoming mail. This issue is fixed in version 7.1.2.

CWE CWE-347
Vendor zammad
Product zammad
Published Sep 25, 2026
Last Updated Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for zammad zammad

Be the first to know when new unknown vulnerabilities affecting zammad zammad are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

zammad / zammad
< 7.1.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/zammad/zammad/security/advisories/GHSA-r957-vp26-563q github.com: https://github.com/zammad/zammad/commit/dd22716ced9f18861ed6f3b326c9d332c8c2072d