CVE-2026-32661 Details
Description
Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote attacker sends a specially crafted request to the product's web service, arbitrary code may be executed when the product is configured to run pop3wallpasswd with grdnwww user privilege.
A stack-based buffer overflow vulnerability has been identified in GUARDIANWALL MailSuite (versions 1.4.00 to 2.4.26) and GUARDIANWALL Mail Security Cloud (SaaS version, prior to the April 30, 2026 maintenance). This vulnerability allows remote attackers to execute arbitrary code by sending specially crafted requests to the product's web service, but only when GUARDIANWALL MailSuite is configured to run the 'pop3wallpasswd' command with 'grdnwww' user privileges.
Users of GUARDIANWALL MailSuite should apply the available patch. Instructions for patching have been sent to users via their support contact. GUARDIANWALL Mail Security Cloud users do not need to take action, as the vulnerability has already been addressed in the April 30, 2026 update.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 13, 2026CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/jp/JVN35567473/ | [email protected] | AdvisoryRemedy |
| https://security-support.canon-its.jp/info_and_news/show/804?site_domain=GUARDIANWALL | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Canon Marketing Japan GUARDIANWALL MailSuite | All versions |
CPE
Remediation
| |
| Canon Marketing Japan GUARDIANWALL Mail Security Cloud | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | New CVE Received | [email protected] |
Volerion