Insecure Processing of PGP-Signed Emails in Zammad Helpdesk System
CVE-2026-56727
What is CVE-2026-56727?
Zammad, a web-based open-source helpdesk platform, faced a significant security issue in its inbound PGP email processing feature prior to version 7.0.2. The vulnerability arises from the system quietly discarding the return value of the GNU Privacy Guard (gpg) verification process. Consequently, regardless of the validity of the gpg signature, Zammad treated all incoming PGP-signed emails as verified, misleading users into believing they were interacting with authentic content. This flaw allows attackers to manipulate or fabricate email signatures, potentially exposing sensitive information or misleading communications. Users relying on Zammad's signature verification feature are urged to upgrade to version 7.0.2 or later to mitigate these risks.
Affected Version(s)
zammad < 7.0.2
