Security Advisory

CVE-2026-13014

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-13 09:42:45
Last updated 2026-07-13 14:07:27
Assigner THA-PSIRT
CVSS score 9.2
State PUBLISHED

Description

A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrarily overwrite writable application files—including Python modules, configuration files, cron inputs, and runtime artifacts—leading to a persistent denial of service, the potential compromise of application secrets or integrations, and root-level execution inside the Django application container. This vulnerability has been names "Matryoshka Mail". Thales PSIRT acknowledges and thanks Lucien Doustaly (aka wlayzz) for discovering and reporting this issue.