Skip to content
Security & Trust

GestSup flaw lets an emailed PHP attachment run on the server

NVD lists an unauthenticated remote code execution path through a monitored mailbox in GestSup versions before 3.2.61

W
WebPulse Newsroom
AI-assisted · 3 min read
Share on X LinkedIn
GestSup flaw lets an emailed PHP attachment run on the server

Photo: Maksim Goncharenok / Pexels

Key finding

CVSS 3.1 base score: 8.1 (High) (Source: NIST NVD record CVE-2026-100389, score assigned by [email protected] (published September 25, 2026))

A remote code execution flaw in GestSup lets an unauthenticated outsider place executable code on the server using an email. The NIST National Vulnerability Database published the record, CVE-2026-100389, on September 25, 2026. It covers GestSup versions before 3.2.61. For an organisation, the notable detail is the entry point: a mailbox the application monitors, not a login page.

What the record describes

According to NVD, GestSup's basic IMAP connector does not skip blocked file extensions when it handles attachments. Unauthenticated attackers can send emails carrying PHP files to a monitored mailbox. The files are written to the upload/ticket directory, which is reachable over the web, and they execute when accessed. The record's vectors show no privileges required and no user interaction.

8.1 (High)
CVSS 3.1 base score
Source: NIST NVD record CVE-2026-100389, score assigned by [email protected] (published September 25, 2026)
9.2 (Critical)
CVSS 4.0 base score
Source: NIST NVD record CVE-2026-100389, score assigned by [email protected] (published September 25, 2026)

Why two scores matter for prioritisation

Both ratings were assigned by the same scorer, [email protected], and both mark confidentiality, integrity and availability impact as high. They differ on prerequisites. The CVSS 3.1 vector records high attack complexity. The CVSS 4.0 vector records low complexity, with an attack requirement flagged as present. The record does not explain the gap. The two numbers, 8.1 and 9.2, sit in different severity bands, so a vulnerability queue that ranks on one version of the scoring system may place this item differently from a queue that ranks on the other.

What the record does not say

The NVD entry does not describe active exploitation, and it gives no figures on how many installations exist. WebPulse does not detect GestSup, so this story includes no scan data on its deployment. The evidence here is the NVD record itself: the affected-version boundary, the mechanism and the scores. NVD lists the GestSup changelog, the GestSup download page and a VulnCheck advisory as references.

Before 3.2.61
Affected versions, per NVD
Source: NIST NVD record CVE-2026-100389 (published September 25, 2026)

Questions to put to your team

1. Do we run GestSup anywhere, including in a subsidiary, a business unit or a service run for us by a vendor? Which version is deployed?

2. Is the IMAP connector enabled, and which mailboxes does it monitor? Who owns those mailboxes and their mail-filtering rules?

3. Does the web server permit script execution in the upload/ticket directory? Has anyone checked that directory for unexpected PHP files since the connector was switched on?

4. If the answer to the first question is yes, is the deployed version before 3.2.61? If so, by what date will it move to a version outside the affected range, and who signs off on it? The GestSup changelog and the VulnCheck advisory listed by NVD are the places to confirm the details.

5. How does our vulnerability tooling handle an item with divergent CVSS 3.1 and 4.0 scores, and did it rank this one consistently?

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: NIST NVD.

CVEs in this analysis
CVE-2026-100389
Share this insight