CVE-2026-84831
nicheMFA enrollment bypass in SEPPmail Secure Email Gateway before 15.0.7
CVE-2026-84831 is a multi-factor authentication bypass (CWE-287/CWE-306) in SEPPmail Secure Email Gateway: the appliance establishes a fully privileged session before the required MFA enrollment process has been completed. An attacker who already possesses the password for an account that is subject to MFA but has not yet finished enrollment can log in and reach protected functionality without supplying a second factor. The attacker gains privileged access to the gateway's protected functions, with the CVSS 4.0 vector rating confidentiality, integrity and availability impact on the vulnerable system as High; the precondition (AT:P) that a targeted MFA-required account is still unenrolled narrows the practical attack window. Organizations running SEPPmail Secure Email Gateway versions before 15.0.7 are affected. No exploitation is currently known: the flaw is not in CISA KEV, no public proof of concept exists, and EPSS assigns a 0.4% probability of exploitation within 30 days (percentile 38).
What to do: Upgrade SEPPmail Secure Email Gateway to 15.0.7 or later, the first fixed release named in the advisory. As an interim mitigation, ensure every MFA-required account completes enrollment immediately after account creation or password reset (only unenrolled accounts are exposed by this flaw), restrict access to the gateway's administration interface to trusted networks, and review authentication logs for privileged logins that were accepted without a second factor.
| SEPPmail Secure Email Gateway | all versions before 15.0.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor.
- Weakness
- CWE-287, CWE-306
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.