A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrarily overwrite writable application files—including Python modules, configuration files, cron inputs, and runtime artifacts—leading to a persistent denial of service, the potential compromise of application secrets or integrations, and root-level execution inside the Django application container.
This vulnerability has been names "Matryoshka Mail".
Thales PSIRT
acknowledges and thanks
Lucien Doustaly (aka wlayzz) for discovering and reporting this issue.
CVSS
No CVSS.
References
Configurations
No configuration.
History
13 Jul 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-13 10:16
Updated : 2026-07-13 19:51
NVD link : CVE-2026-13014
Mitre link : CVE-2026-13014
CVE.ORG link : CVE-2026-13014
JSON object : View
Products Affected
No product.
