CVE-2023-0090: Proofpoint Enterprise Protection

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'. Exploitation requires network access to the webservices API, but such access is a non-standard configuration. This affects all versions 8.20.0 and below.

Affected products

  • Proofpoint Enterprise Protection: before 8.13.22 (fixed in 8.13.22); from 8.18.0, before 8.18.4 (fixed in 8.18.4); version 8.18.6 only; version 8.20.0 only

Published 2023-03-08. Last modified 2026-06-17.