ZeroHour

CVE-2026-84830

niche

Authenticated command injection in SEPPmail Secure Email Gateway

CVSS 4.0
8.6 high
EPSS
1%p63
Published
()
Modified
AI analysis

CVE-2026-84830 is an OS command injection flaw (CWE-78) in SEPPmail Secure Email Gateway that, combined with improper privilege management (CWE-269), allows an authenticated administrator to execute operating-system commands with elevated privileges. It is triggered over the network by sending crafted input to an administrator-reachable function of the gateway; because high privileges are required, the attacker must already hold an administrative account on the appliance, and no user interaction is needed. A successful attacker gains arbitrary command execution with elevated privileges on the gateway itself (high impact to confidentiality, integrity and availability of the appliance), which typically also exposes the email traffic the device processes. Only organizations running SEPPmail Secure Email Gateway versions prior to 15.0.7 are affected; the flaw is fixed in 15.0.7. No public proof-of-concept or in-the-wild exploitation is currently known, and EPSS assigns a 1.1% probability of exploitation within the next 30 days (63rd percentile).

What to do: Upgrade SEPPmail Secure Email Gateway to version 15.0.7 or later. Because exploitation requires authenticated administrator access, restrict the management interface to trusted networks or allowlists, enforce MFA and least privilege on appliance admin accounts, and review appliance logs for unexpected commands or configuration changes made by administrator accounts.

Affected
SEPPmail Secure Email GatewayAll versions before 15.0.7 (fixed in 15.0.7)
Estimated exposure
niche≈ low thousands of deployed gateway appliances — SEPPmail is a specialist enterprise email-security appliance vendor whose per-organization gateways are deployed mainly by banks, insurers and public-sector organizations in Switzerland and neighboring European markets; no public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges.

Weakness
CWE-78, CWE-269
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.