Junglewise Threat Intelligence

CVE-2026-82082: Green-Computing NUMail OS command injection

CVE-2026-82082 · Severity: critical · CVSS 9.8 · Published 2026-08-28

Executive brief

NUMail is an email server application developed by Green-Computing. The product contains an OS command injection vulnerability that allows unauthenticated remote attackers to execute arbitrary system commands on the server, potentially leading to complete system compromise, data theft, and service disruption.

Technical details

NUMail contains an OS command injection vulnerability in an unauthenticated endpoint, allowing remote attackers to inject and execute arbitrary operating system commands without authentication or user interaction. The vulnerability has a CVSS score of 9.8 (critical) with network attack vector, no access controls required, and no privileges needed. An attacker can exploit this to gain full control over the affected server, including reading sensitive data, modifying files, and disrupting service. A patch is available; affected users should update to version 202602162 or later.

Affected products

  • Green-Computing NUMail all versions

Timeline

  • 2026-08-28: disclosed
  • 2026-02-16: patched: Patch version 202602162 or later available

References