SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84831

HIGH · CVSS 7.7 EPSS 0.45%

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

SEPPmail Secure Email Gateway versions prior to 15.0.7 are vulnerable due to the creation of a fully privileged session before the completion of multi-factor authentication enrollment. This flaw allows an attacker with the password of an unenrolled account to bypass the second authentication factor, potentially leading to unauthorized access to sensitive functionalities. Organizations using this email gateway should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-84831
Severity
HIGH
CVSS
7.7
EPSS
0.45%

Original NVD Description

SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor.