CVE-2026-84831

Summary

SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor.

Affected Software

VendorProductVersion RangeStatus
SEPPmail AGSEPPmail Secure Email Gateway (SEG)0 < 15.0.7affected

Weaknesses

  • CWE-287: CWE-287 - Improper Authentication
  • CWE-306: CWE-306 Missing authentication for critical function

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References