CVE-2026-84832

Summary

SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.

Affected Software

VendorProductVersion RangeStatus
SEPPmail AGSEPPmail Secure Email Gateway (SEG)0 < 15.0.6affected

Weaknesses

  • CWE-502: CWE-502 Deserialization of untrusted data
  • CWE-78: CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

Additional References

References