CVE-2026-84831
NONE—CVSS v3
—CVSS v2
0.45%
EPSS (exploit probability)
CWE-287CWE
Description
SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor.
Affected routers (0)
No routers currently mapped to this CVE in our database.