Junglewise Threat Intelligence

CVE-2026-84832: SEPPmail Secure Email Gateway unsafe deserialization in customer import REST endpoint

CVE-2026-84832 · Severity: info · CVSS 8.6 · Published 2026-09-03

Executive brief

SEPPmail Secure Email Gateway is an enterprise email security appliance that filters and processes messages for large organizations. An attacker with a valid privileged API token can exploit unsafe deserialization in the customer import REST endpoint to execute arbitrary system commands, potentially compromising the security gateway and the email infrastructure it protects.

Technical details

The vulnerability is an unsafe deserialization issue in the customer import REST API endpoint that fails to properly validate attacker-controlled input. The flaw allows an authenticated attacker with API token privileges to craft specially formatted input that triggers arbitrary command execution with "nobody" user privileges. The attack requires a valid privileged API token and is delivered through the REST import workflow. SEPPmail addressed this in version 15.0.6 by introducing additional validation and safer command-handling mechanisms to prevent malicious input from being deserialized and executed.

Affected products

  • SEPPmail Secure Email Gateway before 15.0.6

Timeline

  • 2026-09-03: disclosed
  • 2026-09-02: patched: Fixed in version 15.0.7 with additional validation and safer command-handling mechanisms

References