PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-79300 SEP CVE debrief

CVE-2026-79300 SEP sesam MFA Weakness. SEP sesam before 5.2.0.24 mishandles User Authorization with MFA when AD authentication is configured. The difference in username capitalization handling between SEP sesam and Active Directory may allow multiple SEP sesam user accounts to be created for the same AD account. This could potentially allow an additional OTP Authenticator to be registered for the same AD account, reducing MFA protection effectiveness. Defenders should assess exposure, verify MFA effectiveness, and prioritize remediation if vulnerable versions are in use.

Vendor
SEP
Product
sesam
CVSS
LOW 3.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-12
Original CVE updated
2026-09-22
Advisory published
2026-09-12
Advisory updated
2026-09-22

Who should care

Defenders responsible for SEP sesam installations, especially those using AD authentication with MFA, should assess exposure and verify MFA effectiveness. IT teams managing user authentication and authorization in SEP sesam environments should prioritize verifying the current version and configurations.

Why it matters

CVE-2026-79300 describes a weakness in SEP sesam's handling of MFA with AD authentication. Defenders should assess exposure, verify MFA effectiveness, and prioritize remediation if vulnerable versions are in use. The impact on MFA protection requires verification from official sources.

  • Potential reduction in MFA protection effectiveness
  • Possible creation of multiple SEP sesam accounts for the same AD user
  • Need for verification of SEP sesam version and MFA configuration
  • Prioritization of remediation based on exposure assessment

Technical summary

SEP sesam before 5.2.0.24 mishandles User Authorization with MFA when AD authentication is configured. The difference in username capitalization handling between SEP sesam and Active Directory may allow multiple SEP sesam user accounts to be created for the same AD account. This could potentially allow an additional OTP Authenticator to be registered for the same AD account, reducing MFA protection effectiveness.

Defensive priority

Assess exposure, verify MFA effectiveness

Recommended defensive actions

  • Assess exposure: Verify if SEP sesam versions before 5.2.0.24 are in use and if AD authentication with MFA is configured.
  • Verify MFA effectiveness: Review OTP Authenticator registrations for AD accounts in SEP sesam.
  • Inventory check: Identify all instances of SEP sesam in the environment and their current versions.
  • Remediation planning: Prioritize upgrading to SEP sesam 5.2.0.24 or later if vulnerable versions are found.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide details on the MFA weakness in SEP sesam. However, the corpus lacks specific information on affected versions, exploitation, and remediation. Official sources indicate that SEP sesam versions before 5.2.0.24 are vulnerable when AD authentication with MFA is configured. The weakness may allow multiple SEP sesam accounts to be created for the same AD user, potentially reducing MFA protection. Defenders should verify SEP sesam version and MFA configuration, assess exposure, and prioritize remediation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-79300 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-79300

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-79300 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-79300

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.