A critical (CVSS 9.8) OS command injection flaw in Green-Computing's NUMail lets unauthenticated remote attackers execute arbitrary operating system commands on the server.
What Is It
CVE-2026-82082 is an OS command injection vulnerability (CWE-78) in NUMail, a mail product developed by Green-Computing. According to the advisory published by TWCERT/CC, unauthenticated remote attackers can inject arbitrary OS commands and have them executed on the server.
The flaw carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, and a separately assigned CVSS 4.0 base score of 9.3 (CRITICAL). The 3.1 metrics describe the core profile: network attack vector, low attack complexity, no privileges required, and no user interaction, with high impact to confidentiality, integrity, and availability. The two scores land in the same severity band, though the underlying CVSS 4.0 vector string is not present in the supplied data.
Why It Matters
The combination of remote reachability, zero authentication, and low complexity means exploitation requires nothing an attacker does not already have; no credentials, no victim interaction, no unusual preconditions. Successful command injection yields code execution in the context of the mail server process, which the CVSS impact metrics rate as full compromise of confidentiality, integrity, and availability of the vulnerable component.
Mail servers are high-value targets: they hold correspondence, credentials, and routing trust, and they are typically exposed to untrusted networks by design.
What's Vulnerable
- Vendor: Green-Computing
- Product: NUMail
- Affected versions: All versions are listed as affected in the NVD record. No fixed version is enumerated in the supplied data, and no CPE entries are present.
Patch Status
The NVD record is in "Received" status as of its publication on 2026-08-28 and contains no patch, fixed-version, or mitigation details. Administrators should consult the TWCERT/CC advisories linked below for vendor remediation guidance.
This CVE does not appear in the CISA Known Exploited Vulnerabilities catalog, so there is no KEV-confirmed active exploitation and no KEV-mandated required action or remediation due date associated with it at this time.
Sources
- NVD, CVE-2026-82082: https://nvd.nist.gov/vuln/detail/CVE-2026-82082
- TWCERT/CC Advisory (English): https://www.twcert.org.tw/en/cp-139-11145-5361d-2.html
- TWCERT/CC Advisory (Chinese): https://www.twcert.org.tw/tw/cp-132-11144-45c6a-1.html
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog