Executive brief
Canon's GUARDIANWALL MailSuite and Mail Security Cloud, which are used for email security and filtering, contain a critical vulnerability. A remote attacker can send a malicious request to the product's web interface to take control of the system. This could lead to a total compromise of the email security gateway, allowing attackers to access sensitive communications or disrupt mail flow.
Technical details
A stack-based buffer overflow (CWE-121) exists in the 'pop3wallpasswd' command within GUARDIANWALL MailSuite. The vulnerability is reachable via the product's web service. An unauthenticated remote attacker can exploit this by sending a specially crafted request to the web interface. Successful exploitation allows for arbitrary code execution with the privileges of the 'grdnwww' user. This vulnerability has reportedly been exploited in the wild against on-premises installations. Patches are available for on-premises versions, and the SaaS version was remediated during maintenance on April 30, 2026.
Affected products
- Canon Marketing Japan Inc. GUARDIANWALL MailSuite (On-premises) 1.4.00 to 2.4.26
- Canon Marketing Japan Inc. GUARDIANWALL Mail Security Cloud (SaaS) Versions before April 30, 2026 maintenance
Timeline
- 2026-04-30: patched: SaaS version fixed during maintenance
- 2026-05-13: disclosed: Public advisory released
- 2026-05-13: exploited: Developer states attacks have been observed in the wild for on-premises versions