External risk intelligence

GestSup IMAP Connector Attachment Handling Remote Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-100389

GestSup is a help desk and ticketing system designed to be reachable for end-user support interactions. The vulnerability exists in the IMAP connector processing, which requires the application to actively monitor and process incoming emails, a core functional component that is commonly exposed or integrated with public-facing mail infrastructure in real-world help desk deployments.

Unrestricted File Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

GestSup, a help desk and ticketing system, has a vulnerability in its IMAP connector that could allow unauthenticated attackers to execute remote code by sending specially crafted emails with PHP attachments. This could potentially lead to unauthorized access and control of affected systems.

  • Unauthenticated attackers can execute code remotely.
  • Affects help desk systems handling email attachments.
  • Confirm relevance and exposure to protect systems.

Attack Path

How an attacker could exploit the issue

An attacker can achieve remote code execution by sending specially crafted emails to the help desk system. The system's IMAP connector processes attachments, and a flaw allows it to handle disallowed file types, like PHP scripts. If an attacker sends an email with a PHP attachment to a monitored mailbox, the attachment is saved to a web-accessible directory. When this attachment is accessed, the PHP code executes, giving the attacker control.

  • Attacker sends malicious email to monitored mailbox.
  • System saves and executes PHP attachment.
  • Unauthenticated remote code execution.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker could achieve remote code execution by sending specially crafted emails with PHP attachments to monitored mailboxes. This could lead to the execution of arbitrary code on the server when these attachments are accessed.

  • Server-side code execution.
  • Email attachments are processed and stored.
  • Compromised server and data.

Operational Fix

Recommended remediation, mitigation, and detection steps

The vulnerability in GestSup's IMAP connector for handling attachments likely impacts teams responsible for the application's infrastructure and platform operations, as well as potentially the vendor management team if using a SaaS offering. The first practical step is to identify all instances of GestSup, confirm their exposure and business criticality, and then assign an owner to manage the remediation process, which may involve vendor coordination or an upgrade.

  • Application owners and infrastructure teams.
  • Verify GestSup instances and exposure.
  • Plan and coordinate upgrades or vendor fixes.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is GestSup?

GestSup is an open-source help desk and ticketing management system. IT departments and support teams use it to track, organize, and resolve end-user requests by consolidating communication into a central web-based interface.

What does CVE-2026-100389 mean in plain English?

This is an unrestricted file upload vulnerability (CWE-434). The software's email processing component fails to filter out dangerous file types, such as PHP scripts. Because these files are saved directly into a web-accessible folder, the server can accidentally run the attacker's code instead of just storing the attachment.

How does an attacker trigger this vulnerability?

An attacker sends an email containing a malicious PHP file as an attachment to a mailbox monitored by the GestSup IMAP connector. The vulnerability does not trigger if the system is configured to ignore attachments, nor does it trigger if the upload directory is restricted from executing scripts at the server level.

Is my GestSup instance at risk?

According to Halo Surface Signal, risk is high because GestSup is typically deployed to be reachable for public support interactions. If your system monitors an email account that can receive messages from the internet, it is exposed to this remote threat, even if the application is not intended for public login.

What should I do to secure my system?

Start by identifying all deployed versions of GestSup in your environment. Once located, confirm if the IMAP connector is enabled and active. Prioritize upgrading to version 3.2.62 or later to address the file handling flaw, or disable the email attachment processing feature until the update can be applied.

References