Improper Input Validation in Zammad Helpdesk System
CVE-2026-61855

5.3MEDIUM

Key Information:

Vendor

Zammad

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-61855?

The Zammad helpdesk system, an open-source support tool, has a vulnerability affecting versions 7.0.3 and 7.1.1 where the verification process of PGP-signed emails may incorrectly display a message as having a valid signature. This occurs under certain conditions, leading the system to mark an inbound message as secure, despite the content not being properly authenticated. This misrepresentation can mislead support agents relying on the signature for assessing the authenticity of incoming communications. The issue has been resolved in version 7.1.2.

Affected Version(s)

zammad < 7.1.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.