版本早于 15.0.6 的 SEPPmail Secure Email Gateway 在一个拥有特权的 REST 导入工作流中,对攻击者可控的数据进行反序列化,且缺乏充分的验证。拥有特权 API 令牌的攻击者可以以“nobody”权限执行任意命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SEPPmail AG | SEPPmail Secure Email Gateway (SEG) | < 15.0.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SEPPmail AG | SEPPmail Secure Email Gateway (SEG) | 0 ~ 15.0.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84830 | 8.6 HIGH | OS command injection in privileged configuration handling |
| CVE-2026-84831 | 7.7 HIGH | Mandatory MFA bypass before enrollment |
No comments yet