CVE-2026-61855
Received Received - Intake

PGP Signature Validation Bypass in Zammad

Vulnerability report for CVE-2026-61855, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: GitHub, Inc.

Description

Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, under certain conditions, Zammad's verification of inbound PGP-signed email can mark a message as carrying a valid ("Good") PGP signature from a registered sender key, even though the displayed message content is not actually covered by that signature. As a result, the inbound article may be stored with a successful signature status that does not reflect the authenticity of the shown content. This can mislead agents who rely on the signature indicator when assessing the trustworthiness of incoming mail. This issue is fixed in version 7.1.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zammad zammad 7.1.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Zammad is a helpdesk system that verifies PGP-signed emails. In versions 7.0.3 and 7.1.1, it incorrectly marks emails as having a valid PGP signature even when the displayed content is not covered by that signature. This misleads agents relying on signature indicators to assess email trustworthiness.

Detection Guidance

This vulnerability involves Zammad incorrectly verifying PGP-signed emails, leading to false signature status. To detect it, check Zammad logs for inbound emails marked as having valid PGP signatures but where the content does not match the signature. Review email headers and stored articles for discrepancies between the signature status and actual message content.

Impact Analysis

Agents may trust emails marked as PGP-signed when the content is not authentic. This could lead to misinformation being processed as legitimate, potentially causing incorrect responses or data handling based on unverified information.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing misleading PGP signature indicators to be stored with inbound articles. Agents relying on these indicators may incorrectly assess the authenticity of incoming mail, which could lead to unauthorized access or mishandling of sensitive data.

Mitigation Strategies

Upgrade Zammad to version 7.1.2 or later to address the PGP signature verification issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-61855. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart