Junglewise Threat Intelligence

CVE-2026-84831: SEPPmail Secure Email Gateway MFA bypass in authentication

CVE-2026-84831 · Severity: info · CVSS 7.7 · Published 2026-09-03

Executive brief

SEPPmail Secure Email Gateway is an email security appliance that enforces multi-factor authentication (MFA) to protect administrative and user accounts. A vulnerability in versions before 15.0.7 allows attackers with valid account credentials to bypass mandatory MFA enrollment and gain full access to protected functionality without providing a second authentication factor, potentially exposing the email system to unauthorized administrative control.

Technical details

The vulnerability exists in the authentication flow of SEPPmail Secure Email Gateway versions before 15.0.7, where a fully privileged session is created before completion of required multi-factor authentication enrollment. An attacker with valid password credentials for an MFA-required but unenrolled account can exploit this timing gap to access protected administrative or user functionality without providing the mandatory second factor. The attack requires knowledge of a valid username and password; no network authentication bypass is needed beyond standard login. The fix in 15.0.7 tightens the authentication flow to ensure all required MFA checks are completed before any privileged session is established. A related advisory mentions this was tracked as internal reference SEC-100 with a pending CVE assignment separate from CVE-2026-84831.

Affected products

  • SEPPmail Secure Email Gateway before 15.0.7

Timeline

  • 2026-09-03: disclosed

References