PT-2026-82868 · Green Computing · Gnumail
CVE-2026-82082
·
Published
2026-08-28
·
Updated
2026-08-29
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NUMail versions prior to 202602162
Description
NUMail contains an OS Command Injection flaw that allows unauthenticated remote attackers to inject and execute arbitrary operating-system commands on the server. This occurs because the application fails to safely neutralize malicious input before it reaches an operating-system command context, potentially leading to full server compromise, exposure of stored credentials, and access to mail-related data.
Recommendations
Update to version 202602162 or the corresponding corrected release provided by Green-Computing.
Restrict unnecessary internet exposure to the service.
Inspect web and application logs for unusual parameters.
Review processes spawned by the NUMail service for unexpected shell execution, such as
sh, bash, cmd, powershell, curl, wget, or python.Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gnumail