Remote Code Execution in GestSup IMAP Connector Attachment Handling
CVE-2026-100389
9.2CRITICAL
What is CVE-2026-100389?
Versions of GestSup prior to 3.2.61 are susceptible to a remote code execution vulnerability within the basic IMAP connector's attachment management. The flaw arises from improper handling of blocked file extensions, allowing unauthenticated attackers to craft and send emails containing malicious PHP attachments. These attachments are subsequently written to the web-accessible upload/ticket directory, leading to their execution when accessed. This vulnerability necessitates immediate attention to ensure protection against unauthorized remote execution and potential system compromise.
Affected Version(s)
GestSup 0 < 3.2.61
