Loading market data...
← Back to CVE feed

CVE-2026-84832

UNKNOWN View on NVD ↗

Description

SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.

Published: Sep 03, 2026 13:06 UTC Modified: Sep 03, 2026 18:14 UTC