๐Ÿ” CVE Alert

CVE-2026-84831

UNKNOWN 0.0

Mandatory MFA bypass before enrollment

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor.

CWE CWE-287 CWE-306
Vendor seppmail ag
Product seppmail secure email gateway (seg)
Published Sep 3, 2026
Last Updated Sep 3, 2026
Stay Ahead of the Next One

Get instant alerts for seppmail ag seppmail secure email gateway (seg)

Be the first to know when new unknown vulnerabilities affecting seppmail ag seppmail secure email gateway (seg) are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

SEPPmail AG / SEPPmail Secure Email Gateway (SEG)
0 < 15.0.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
downloads.seppmail.com: https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html

Credits

Emposo GmbH