CVE-2026-61855
Descriptive record received from OpenCTI and minimised for consultation in the Intel portal.
- Sharing
- PUBLIC-OSINT
- Confidence
- 100
- Source
- The CVE Program
- Updated
- 26/09/2026 02:01
Description
Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, under certain conditions, Zammad's verification of inbound PGP-signed email can mark a message as carrying a valid ("Good") PGP signature from a registered sender key, even though the displayed message content is not actually covered by that signature. As a result, the inbound article may be stored with a successful signature status that does not reflect the authenticity of the shown content. This can mislead agents who rely on the signature indicator when assessing the trustworthiness of incoming mail. This issue is fixed in version 7.1.2.
Aliases and classifications
Minimised technical details
No raw data- cisa kev
- False
Public references
- https://github.com/zammad/zammad/security/advisories/GHSA-r957-vp26-563q
https://github.com/zammad/zammad/security/advisories/GHSA-r957-vp26-563q - https://github.com/zammad/zammad/commit/dd22716ced9f18861ed6f3b326c9d332c8c2072d
https://github.com/zammad/zammad/commit/dd22716ced9f18861ed6f3b326c9d332c8c2072d
Intel catalogue
The vulnerability is also available in the EudorIA editorial catalogue.
Open EudorIA analysisPresence in OpenCTI describes an intelligence correlation and does not, by itself, constitute evidence of compromise, legal attribution or operational guidance applicable without context verification.