Improper Input Validation in Zammad Helpdesk System
CVE-2026-61855
5.3MEDIUM
What is CVE-2026-61855?
The Zammad helpdesk system, an open-source support tool, has a vulnerability affecting versions 7.0.3 and 7.1.1 where the verification process of PGP-signed emails may incorrectly display a message as having a valid signature. This occurs under certain conditions, leading the system to mark an inbound message as secure, despite the content not being properly authenticated. This misrepresentation can mislead support agents relying on the signature for assessing the authenticity of incoming communications. The issue has been resolved in version 7.1.2.
Affected Version(s)
zammad < 7.1.2
