CVE-2026-84832: Seppmail AG Seppmail Secure Email Gateway Seg

High severity, CVSS 8.6. EPSS: 0.6% chance of exploitation in the next 30 days.

SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.

Affected products

  • Seppmail AG Seppmail Secure Email Gateway Seg: before 15.0.6 (fixed in 15.0.6)

Published 2026-09-03. Last modified 2026-09-04.