CVE-2026-79300
Received Received - Intake

Authentication Bypass via MFA Misconfiguration in SEP sesam

Vulnerability report for CVE-2026-79300, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-12

Last updated on: 2026-09-12

Assigner: MITRE

Description

SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can create a second OTP access capability. SEP sesam and Active Directory handle username capitalization differently, which may allow multiple SEP sesam user accounts to be created for the same Active Directory (AD) account. Active Directory treats usernames as case-insensitive, while SEP sesam distinguishes between different letter casing. As a result, the same AD user can be represented by multiple SEP sesam user accounts that differ only in username capitalization. When Active Directory authentication is configured and multi-factor authentication (MFA) is enforced, this behavior may allow an additional OTP Authenticator to be registered for the same AD account, reducing the effectiveness of MFA protection.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-12
Last Modified
2026-09-12
Generated
2026-09-13
AI Q&A
2026-09-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sep_sesam sep_sesam to 5.2.0.24 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-180 The product validates input before it is canonicalized, which prevents the product from detecting data that becomes invalid after the canonicalization step.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SEP sesam before version 5.2.0.24 has a flaw in user authorization when using Active Directory (AD) authentication with enforced multi-factor authentication (MFA). The issue arises because SEP sesam treats usernames as case-sensitive while AD treats them as case-insensitive. This allows an attacker to create multiple SEP sesam accounts for the same AD user by varying the capitalization of the username.

Detection Guidance

Check SEP sesam user accounts for duplicates with varying capitalization of the same AD username. Review MFA authenticator registrations for inconsistencies. Verify SEP sesam version is below 5.2.0.24.

Impact Analysis

This vulnerability could allow an attacker to bypass MFA protections by registering an additional OTP authenticator for the same AD account. This reduces the security of MFA, potentially allowing unauthorized access to SEP sesam systems even when MFA is enforced.

Mitigation Strategies

Upgrade SEP sesam to version 5.2.0.24 or later. Review and consolidate user accounts to ensure no duplicate entries exist. Reconfigure MFA settings to enforce case-insensitive username handling.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79300. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart