CVE-2026-84832
nicheInsecure Deserialization RCE in SEPPmail Secure Email Gateway REST Import
SEPPmail Secure Email Gateway before 15.0.6 insecurely deserializes attacker-controlled data (CWE-502) in a privileged REST import workflow without adequate validation, enabling command injection (CWE-78). The flaw is triggered when an attacker holding a privileged API token submits crafted serialized data to the gateway's REST import function. Successful exploitation yields execution of arbitrary operating-system commands on the appliance under the low-privilege 'nobody' account, though the CVSS 4.0 scoring still rates the confidentiality, integrity and availability impact as high. All deployments running versions earlier than 15.0.6, typically enterprise and service-provider email-security appliances, are affected, particularly where the REST API is reachable by third parties or where privileged API tokens may be compromised. No public proof of concept, CISA KEV listing, or confirmed in-the-wild exploitation is currently known, and EPSS estimates only about a 0.6% probability of exploitation within 30 days.
What to do: Upgrade to SEPPmail Secure Email Gateway 15.0.6 or later. Until patched, restrict access to the REST API (e.g., management-network allowlisting), apply least-privilege to and rotate any privileged API tokens, and review appliance logs for unexpected import activity or commands executed as 'nobody'.
| SEPPmail Secure Email Gateway | before 15.0.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.
- Weakness
- CWE-78, CWE-502
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.