CVE-2026-84832

8.6

SEPPmail AG · SEPPmail Secure Email Gateway (SEG)

SEPPmail Secure Email Gateway before 15.0.6 is vulnerable to insecure deserialization and OS command injection in a privileged REST API workflow.

Executive summary

An authenticated remote code execution vulnerability in SEPPmail Secure Email Gateway allows attackers with privileged access to execute arbitrary commands on the appliance.

Vulnerability

This vulnerability involves improper deserialization of untrusted data (CWE-502) and OS command injection (CWE-78) within a privileged REST import workflow. The flaw permits an attacker who possesses a valid, privileged API token to execute arbitrary commands with the privileges of the nobody user.

Business impact

The ability to execute arbitrary commands on a Secure Email Gateway presents a significant risk to organizational confidentiality and integrity. If compromised, an attacker could potentially intercept, modify, or exfiltrate sensitive email traffic, leading to data breaches or further lateral movement within the network. With a CVSS score of 8.6, this high severity vulnerability necessitates immediate attention to prevent unauthorized administrative control over critical communication infrastructure.

Remediation

Immediate Action: Update the SEPPmail Secure Email Gateway to version 15.0.6 or later immediately to apply the necessary input validation fixes.

Proactive Monitoring: Review REST API access logs for suspicious import activity or unexpected command execution patterns associated with administrative service accounts.

Compensating Controls: Restrict access to the REST API interface to known, trusted IP addresses and rotate any API tokens that may have been exposed or are currently held by untrusted entities.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical role of email gateways in protecting organizational data, this vulnerability represents a substantial security risk. Administrators should prioritize the deployment of version 15.0.6 across all affected SEG appliances to neutralize the risk of command injection. Ensure that API token management policies are strictly enforced to minimize the attack surface while the update is being staged.

More SEPPmail AG CVEs

Sources

Originally found and disclosed by Emposo GmbH, per the CVE Program record.