Remote Code Execution in GestSup IMAP Connector Attachment Handling
CVE-2026-100389

9.2CRITICAL

Key Information:

Vendor

Gestsup

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-100389?

Versions of GestSup prior to 3.2.61 are susceptible to a remote code execution vulnerability within the basic IMAP connector's attachment management. The flaw arises from improper handling of blocked file extensions, allowing unauthenticated attackers to craft and send emails containing malicious PHP attachments. These attachments are subsequently written to the web-accessible upload/ticket directory, leading to their execution when accessed. This vulnerability necessitates immediate attention to ensure protection against unauthorized remote execution and potential system compromise.

Affected Version(s)

GestSup 0 < 3.2.61

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SpiizN
.