PT-2026-84958 · Seppmail Ag · Seppmail Secure Email Gateway

·

CVE-2026-84832

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.

Exploit

Fix

Deserialization of Untrusted Data

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84832

Affected Products

Seppmail Secure Email Gateway