PT-2026-90723 · Sep · Sesam
CVE-2026-79300
·
Published
2026-09-12
·
Updated
2026-09-22
CVSS v3.1
3.5
Low
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SEP sesam versions prior to 5.2.0.24
Description
An issue exists in the handling of user authorization when multi-factor authentication (MFA) is enforced and Active Directory (AD) authentication is configured. Because Active Directory treats usernames as case-insensitive while SEP sesam distinguishes between different letter casing, multiple SEP sesam accounts can be created for a single AD account by varying the capitalization of the username. This discrepancy allows an attacker to register an additional One-Time Password (OTP) authenticator for the same AD account, which reduces the effectiveness of the MFA protection.
Recommendations
Update SEP sesam to version 5.2.0.24 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sesam