Junglewise Threat Intelligence

CVE-2026-84830: SEPPmail Secure Email Gateway command injection in configuration handling

CVE-2026-84830 · Severity: info · CVSS 8.6 · Published 2026-09-03

Executive brief

SEPPmail Secure Email Gateway is an email security appliance that protects organizations from email-based threats. A command injection vulnerability in privileged configuration handling allows authenticated administrators to execute arbitrary operating system commands with elevated privileges, potentially compromising the entire email gateway and enabling lateral movement into the organization's network.

Technical details

The vulnerability is an OS command injection flaw in the privileged configuration handling component of SEPPmail Secure Email Gateway versions before 15.0.7. The affected code fails to properly escape or sanitize administrator-supplied input before passing it to system commands, allowing an authenticated administrator to inject arbitrary OS commands that execute with elevated privileges. Attack precondition requires valid administrator credentials. The fix in version 15.0.7 implements proper escaping of all affected configuration values. Patch availability: version 15.0.7 released September 2, 2026.

Affected products

  • SEPPmail Secure Email Gateway before 15.0.7

Timeline

  • 2026-09-03: disclosed
  • 2026-09-02: patched: Fixed in version 15.0.7

References