CVE-2026-61855
— UNSCOREDpublic exploit availablePublished 2026-09-25 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, under certain conditions, Zammad's verification of inbound PGP-signed email can mark a message as carrying a valid ("Good") PGP signature from a registered sender key, even though the displayed message content is not actually covered by that signature. As a result, the inbound article may be stored with a successful signature status that does not reflect the authenticity of the shown content. This can mislead agents who rely on the signature indicator when assessing the trustworthiness of incoming mail. This issue is fixed in version 7.1.2.
Weaknesses
CWE-347
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2025-71422PoC
- HIGHCVE-2026-100293
- HIGHCVE-2026-102266PoC
- CRITICALCVE-2026-102268PoC
- HIGHCVE-2026-102271PoC
- HIGHCVE-2026-102272PoC
- HIGHCVE-2026-102273PoC
- UNSCOREDCVE-2026-102508
Related by shared AI tags and CWE weakness class. Browse the full archive.