SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-03 13:06
Updated : 2026-09-04 17:17
NVD link : CVE-2026-84832
Mitre link : CVE-2026-84832
CVE.ORG link : CVE-2026-84832
JSON object : View
Products Affected
No product.
