{"id":"CVE-2026-84832","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-84832","summary":"SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API…","details":"SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with \"nobody\" privileges.","published":"2026-09-03T13:06:18.887","modified":"2026-09-03T13:06:18.887","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html"},{"type":"WEB","url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-pp65-5j34-grgc"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-03T13:06:18.887"}}