CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100389

HIGHCVSS 8.1NVD feed

Published 25 September 2026 · tracked since 26 September 2026

Description

GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible up

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100389 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100389

HIGHCVSS 8.1NVD feed

Published 25 September 2026 · tracked since 26 September 2026

Description

GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible up

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]