PT-2025-10626 · Mozilla+6 · Thunderbird+6

Marcus Brinkmann

·

Published

2025-02-13

·

Updated

2025-07-22

·

CVE-2025-26696

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Thunderbird versions prior to 136 Thunderbird versions prior to 128.8
Description The issue arises from certain crafted MIME email messages that claim to contain an encrypted OpenPGP message but actually contain an OpenPGP signed message, which are wrongly shown as being encrypted.
Recommendations For versions prior to 136, update to version 136 or later. For versions prior to 128.8, update to version 128.8 or later.

Fix

UI Misrepresentation of Critical Information

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

ALT-PU-2025-7695
BDU:2025-02512
CVE-2025-26696
DLA-4081-1
DSA-5876-1
OPENSUSE-SU-2025_0849-1
SUSE-SU-2025:0849-1
USN-7663-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Red Os
Suse
Thunderbird
Ubuntu