CVE-2026-84832: Unsafe deserialization in the REST interface
Published Sep 3, 2026
·Updated
SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.
Affected Software
1 affected component
SEPPmail Secure Email Gateway<15.0.6
Event History
Sep 3, 2026
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs a privileged API token and access to the REST import workflow. The issue affects SEPPmail Secure Email Gateway versions before 15.0.6.
2
What level of access could an attacker obtain?
Successful exploitation allows arbitrary command execution with the privileges of the "nobody" user.
3
Is the REST interface affected in every use case?
The described vulnerable path is the privileged REST import workflow. The provided information does not establish whether other REST endpoints or unprivileged API tokens are affected.