CVE-2026-84832EPSS p48.7%
CVE-2026-84832CVE-2026-84832
Description
SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.
Scoring
| EPSS | 0.64% probability of exploitation · percentile 48.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-04 |