PT-2026-90723 · Sep · Sesam

CVE-2026-79300

·

Published

2026-09-12

·

Updated

2026-09-22

CVSS v3.1

3.5

Low

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SEP sesam versions prior to 5.2.0.24
Description An issue exists in the handling of user authorization when multi-factor authentication (MFA) is enforced and Active Directory (AD) authentication is configured. Because Active Directory treats usernames as case-insensitive while SEP sesam distinguishes between different letter casing, multiple SEP sesam accounts can be created for a single AD account by varying the capitalization of the username. This discrepancy allows an attacker to register an additional One-Time Password (OTP) authenticator for the same AD account, which reduces the effectiveness of the MFA protection.
Recommendations Update SEP sesam to version 5.2.0.24 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79300

Affected Products

Sesam