GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 25 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed.
Title GestSup before 3.2.61 Remote Code Execution via IMAP Attachment
First Time appeared Gestsup
Gestsup gestsup
Weaknesses CWE-434
CPEs cpe:2.3:a:gestsup:gestsup:*:*:*:*:*:*:*:*
Vendors & Products Gestsup
Gestsup gestsup
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-25T20:13:07.623Z

Reserved: 2026-09-25T19:47:52.073Z

Link: CVE-2026-100389

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-25T21:17:22.483

Modified: 2026-09-25T21:17:22.483

Link: CVE-2026-100389

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T22:00:20Z

Weaknesses