CRITICAL
GestSup
CVE published 2026-09-25
CVE-2026-100389
CVE-2026-100389 is a critical remote code execution vulnerability in GestSup versions before 3.2.61. The vulnerability exists in the basic IMAP connector's attachment handling, which fails to skip blocked file extensions. Unauthenticated attackers can exploit this by sending emails with PHP attachments to monitored mailboxes, which are then written to the web-accessible upload/ticket directory and execute [truncated]