CVE-2026-84832
NONE—CVSS v3
—CVSS v2
0.61%
EPSS (exploit probability)
CWE-78CWE
Description
SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.
Affected routers (0)
No routers currently mapped to this CVE in our database.