Improper Certificate Validation in Zammad - CVE-2026-84465
Published: October 3, 2026
Vulnerability details
The vulnerability allows a remote attacker to impersonate a trusted sender.
The vulnerability exists due to improper certificate validation in S/MIME signature verification when checking incoming S/MIME-signed emails. A remote attacker can create a certificate using the name of a previously trusted sender and send a forged signed email to impersonate a trusted sender.
User interaction is required.