SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84832

HIGH · CVSS 8.6 EPSS 0.61%

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The SEPPmail Secure Email Gateway prior to version 15.0.6 is vulnerable due to improper validation of deserialized data in a privileged REST import workflow. This flaw allows an attacker with a valid API token to execute arbitrary commands with "nobody" privileges, potentially compromising the system's integrity. Organizations using this email gateway should prioritize remediation to mitigate the risk of unauthorized command execution.

CVE
CVE-2026-84832
Severity
HIGH
CVSS
8.6
EPSS
0.61%

Original NVD Description

SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.