Deserialization Flaw in SEPPmail Secure Email Gateway Affects Security Protocols
CVE-2026-84832

8.6HIGH

Key Information:

Vendor
CVE Published:
3 September 2026

What is CVE-2026-84832?

The SEPPmail Secure Email Gateway prior to version 15.0.6 contains a deserialization vulnerability that arises during a privileged REST import workflow. In this scenario, insufficient validation allows attackers with access to a privileged API token to inject malicious data. If exploited, this flaw enables the execution of arbitrary commands under the context of the 'nobody' user, posing significant security risks.

Affected Version(s)

SEPPmail Secure Email Gateway (SEG) 0 < 15.0.6

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Emposo GmbH
.