CVE-2026-84832
Unsafe deserialization in the REST interface
Description
SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.
INFO
Published Date :
Sept. 3, 2026, 8:45 a.m.
Last Modified :
Sept. 3, 2026, 8:45 a.m.
Remotely Exploit :
Yes !
Source :
NCSC.ch
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 4.0 | HIGH | 455daabc-a392-441d-aa46-37d35189897c |
Solution
- Update SEPPmail to version 15.0.6 or later.
- Validate input data in import workflows.
- Restrict API token privileges.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-84832 vulnerability anywhere in the article.