CVE-2026-84831
Received Received - Intake

SEPPmail Secure Email Gateway Session Bypass Before MFA Enrollment

Vulnerability report for CVE-2026-84831, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: Switzerland Government Common Vulnerability Program

Description

SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-03
AI Q&A
2026-09-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
seppmail secure_email_gateway to 15.0.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects SEPPmail Secure Email Gateway versions before 15.0.7. It allows an attacker with a valid password for an account that requires multi-factor authentication (MFA) to access protected features without completing MFA enrollment. The system creates a fully privileged session prematurely, bypassing the second authentication factor.

Impact Analysis

An attacker could gain unauthorized access to sensitive email gateway functions using only a password. This may lead to data breaches, unauthorized email sending or interception, and potential compromise of protected communications. Systems relying on MFA for security are at risk.

Compliance Impact

This vulnerability could violate compliance requirements that mandate strong authentication for sensitive data access, such as GDPR's security principle or HIPAA's access controls. Unauthorized access risks data exposure, leading to potential regulatory penalties and loss of trust.

Mitigation Strategies

Update SEPPmail Secure Email Gateway to version 15.0.7 or later to ensure multi-factor authentication is enforced before session creation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84831. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart