CVE-2026-84831
Mandatory MFA bypass before enrollment
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor.
| CWE | CWE-287 CWE-306 |
| Vendor | seppmail ag |
| Product | seppmail secure email gateway (seg) |
| Published | Sep 3, 2026 |
| Last Updated | Sep 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for seppmail ag seppmail secure email gateway (seg)
Be the first to know when new unknown vulnerabilities affecting seppmail ag seppmail secure email gateway (seg) are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
SEPPmail AG / SEPPmail Secure Email Gateway (SEG)
0 < 15.0.7
References
Credits
Emposo GmbH