Insecure Processing of PGP-Signed Emails in Zammad Helpdesk System
CVE-2026-56727

7.1HIGH

Key Information:

Vendor

Zammad

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-56727?

Zammad, a web-based open-source helpdesk platform, faced a significant security issue in its inbound PGP email processing feature prior to version 7.0.2. The vulnerability arises from the system quietly discarding the return value of the GNU Privacy Guard (gpg) verification process. Consequently, regardless of the validity of the gpg signature, Zammad treated all incoming PGP-signed emails as verified, misleading users into believing they were interacting with authentic content. This flaw allows attackers to manipulate or fabricate email signatures, potentially exposing sensitive information or misleading communications. Users relying on Zammad's signature verification feature are urged to upgrade to version 7.0.2 or later to mitigate these risks.

Affected Version(s)

zammad < 7.0.2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.