CVE-2026-84832
EUVD-2026-7036403.09.2026, 13:06
SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.
Awaiting analysis
This vulnerability is currently awaiting analysis.