CVE-2026-84830
nicheAuthenticated command injection in SEPPmail Secure Email Gateway
CVE-2026-84830 is an OS command injection flaw (CWE-78) in SEPPmail Secure Email Gateway that, combined with improper privilege management (CWE-269), allows an authenticated administrator to execute operating-system commands with elevated privileges. It is triggered over the network by sending crafted input to an administrator-reachable function of the gateway; because high privileges are required, the attacker must already hold an administrative account on the appliance, and no user interaction is needed. A successful attacker gains arbitrary command execution with elevated privileges on the gateway itself (high impact to confidentiality, integrity and availability of the appliance), which typically also exposes the email traffic the device processes. Only organizations running SEPPmail Secure Email Gateway versions prior to 15.0.7 are affected; the flaw is fixed in 15.0.7. No public proof-of-concept or in-the-wild exploitation is currently known, and EPSS assigns a 1.1% probability of exploitation within the next 30 days (63rd percentile).
What to do: Upgrade SEPPmail Secure Email Gateway to version 15.0.7 or later. Because exploitation requires authenticated administrator access, restrict the management interface to trusted networks or allowlists, enforce MFA and least privilege on appliance admin accounts, and review appliance logs for unexpected commands or configuration changes made by administrator accounts.
| SEPPmail Secure Email Gateway | All versions before 15.0.7 (fixed in 15.0.7) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges.
- Weakness
- CWE-78, CWE-269
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.