---
id: CVE-2026-13014
title: "A vulnerability in\_Thales CERT \"Suspicious\" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and\_arbitrarily overwrite writable application files—including Python modules, configuration files, c…"
summary: "A vulnerability in\_Thales CERT \"Suspicious\" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and\_arbitrarily overwrite writable application files—including Python modules, configuration files, c…"
severity: none
cwe:
  - CWE-22
  - CWE-73
  - CWE-94
published: '2026-07-13'
updated: '2026-07-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13014'
references:
  - url: >-
      https://github.com/thalesgroup-cert/suspicious/security/advisories/GHSA-x85x-9mrm-wwvp
    label: psirt@thalesgroup.com
tags:
  - nvd
ingestedAt: '2026-07-13T12:26:58.209Z'
epss: 0.00704
epssPercentile: 0.51909
---

## Overview

A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrarily overwrite writable application files—including Python modules, configuration files, cron inputs, and runtime artifacts—leading to a persistent denial of service, the potential compromise of application secrets or integrations, and root-level execution inside the Django application container.
This vulnerability has been names "Matryoshka Mail".
Thales PSIRT 
acknowledges and thanks

Lucien Doustaly (aka wlayzz) for discovering and reporting this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
