CVE-2026-84465
Received Received - Intake

S/MIME Signature Spoofing in Zammad

Vulnerability report for CVE-2026-84465, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: GitHub, Inc.

Description

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the digital signature on an incoming S/MIME-signed email, it does not verify that the signing certificate is genuinely trusted, it only checks whether a certificate with a matching name is already stored in the system. An attacker can create their own certificate using the name of a real, previously trusted sender and use it to send a forged email. Zammad will display that email with the same "validly signed" indicator as a genuine message from the real sender, even though the attacker never had access to that sender's actual certificate or private key. This issue is fixed in version 7.1.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zammad zammad 7.1.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
CWE-295 The product does not validate, or incorrectly validates, a certificate.
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Zammad is a helpdesk system that checks digital signatures on S/MIME-signed emails. Prior to version 7.1.2, it only verified if a certificate with a matching name existed in the system, not if it was genuinely trusted. Attackers could create fake certificates using a trusted sender's name to forge emails, which Zammad would display as validly signed.

Impact Analysis

This vulnerability allows attackers to send forged emails that appear to be legitimately signed by trusted senders. Users may trust and act on these emails, leading to potential data breaches, misinformation, or unauthorized actions based on fake communications.

Compliance Impact

This vulnerability could undermine compliance with GDPR and HIPAA by enabling unauthorized access to sensitive data through forged emails. Organizations may fail to meet requirements for secure communication and data integrity if such emails are trusted and acted upon.

Mitigation Strategies

Upgrade Zammad to version 7.1.2 or later to address the S/MIME signature verification flaw. Review all stored certificates and remove any untrusted or duplicate entries that may have been added.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84465. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart