PT-2025-10626 · Mozilla+6 · Thunderbird+6
Marcus Brinkmann
·
Published
2025-02-13
·
Updated
2025-07-22
·
CVE-2025-26696
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Thunderbird versions prior to 136
Thunderbird versions prior to 128.8
Description
The issue arises from certain crafted MIME email messages that claim to contain an encrypted OpenPGP message but actually contain an OpenPGP signed message, which are wrongly shown as being encrypted.
Recommendations
For versions prior to 136, update to version 136 or later.
For versions prior to 128.8, update to version 128.8 or later.
Fix
UI Misrepresentation of Critical Information
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Red Os
Suse
Thunderbird
Ubuntu