CVE-2026-84832
SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.
- Published Sep 3, 2026
- CVSS 8.6 high
- 0.6% chance of exploitation in the next 30 days (EPSS)
- A fix is available