---
id: CVE-2026-100389
title: >-
  GestSup versions before 3.2.61 contain a remote code execution vulnerability
  in the basic IMAP connector's attachment handling that fails to skip blocked
  file extensions
summary: >-
  GestSup versions before 3.2.61 contain a remote code execution vulnerability
  in the basic IMAP connector's attachment handling that fails to skip blocked
  file extensions. Unauthenticated attackers can send emails with PHP
  attachments to …
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
vendor: GestSup
product: GestSup
affected:
  - GestSup < 3.2.61
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T21:17:22.483'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100389'
references:
  - url: 'https://gestsup.fr/index.php?page=changelog'
    label: disclosure@vulncheck.com
  - url: 'https://gestsup.fr/index.php?page=download'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/gestsup-before-3.2.61-remote-code-execution-via-imap-attachment
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T21:19:40.142Z'
---

## Overview

GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
