CVE-2026-84832
Unsafe deserialization in the REST interface
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.
| CWE | CWE-502 CWE-78 |
| Vendor | seppmail ag |
| Product | seppmail secure email gateway (seg) |
| Published | Sep 3, 2026 |
| Last Updated | Sep 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for seppmail ag seppmail secure email gateway (seg)
Be the first to know when new unknown vulnerabilities affecting seppmail ag seppmail secure email gateway (seg) are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
SEPPmail AG / SEPPmail Secure Email Gateway (SEG)
0 < 15.0.6
References
Credits
Emposo GmbH