PT-2026-99109 · Gestsup · Gestsup

·

CVE-2026-100389

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GestSup versions prior to 3.2.61
Description An issue exists in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails containing PHP attachments to monitored mailboxes. These files are then written to the web-accessible upload/ticket directory and can be executed upon access, leading to remote code execution.
Recommendations Update GestSup to version 3.2.61 or later.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100389

Affected Products

Gestsup