Description
Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote attacker sends a specially crafted request to the product's web service, arbitrary code may be executed when the product is configured to run pop3wallpasswd with grdnwww user privilege.
Published: 2026-05-13
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Stack-based buffer overflow in the web service of Canon Marketing Japan Inc.’s GUARDIANWALL MailSuite and Mail Security Cloud allows a remote attacker to send a crafted request and execute arbitrary code. Triggered when the product runs pop3wallpasswd with the grdnwww user account, the flaw maps to CWE‑121 and could compromise the confidentiality, integrity, and availability of the host if the privileged user has broad access.

Affected Systems

Canon Marketing Japan Inc.’s GUARDIANWALL Mail Security Cloud (SaaS version) and GUARDIANWALL MailSuite (On‑premises version) are affected. Specific versions are not disclosed, so all current deployments of these products should be checked for the presence of the vulnerability and for any available updates.

Risk and Exploitability

The CVSS score of 9.3 classifies this flaw as critical. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high exploitation potential is reflected in the score. The attack vector is remote over HTTP/S to the product’s web service. If exploited, arbitrary code runs with the privileges of the grdnwww user, allowing attackers to modify configurations, exfiltrate data, or install additional malware. The lack of an official patch in the advisory means that administrators must rely on configuration hardening and network segmentation to reduce exposure.

Generated by OpenCVE AI on May 13, 2026 at 07:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest vendor patch or firmware update for GUARDIANWALL MailSuite and Mail Security Cloud once available from Canon Marketing Japan Inc.
  • Limit exposure of the web service by restricting inbound access to trusted IP ranges or applying firewall rules, especially when pop3wallpasswd runs with privileged accounts.
  • Reconfigure or disable pop3wallpasswd under the grdnwww user if it is not required, or change its permissions to reduce privilege before deploying the service.

Generated by OpenCVE AI on May 13, 2026 at 07:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 13 May 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 13 May 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Canon Marketing Japan
Canon Marketing Japan guardianwall Mail Security Cloud (saas Version)
Canon Marketing Japan guardianwall Mailsuite (on-premises Version)
Vendors & Products Canon Marketing Japan
Canon Marketing Japan guardianwall Mail Security Cloud (saas Version)
Canon Marketing Japan guardianwall Mailsuite (on-premises Version)

Wed, 13 May 2026 08:15:00 +0000


Wed, 13 May 2026 07:30:00 +0000

Type Values Removed Values Added
Title Stack Buffer Overflow in GUARDIANWALL MailSuite Web Service Enables Remote Code Execution

Wed, 13 May 2026 06:00:00 +0000

Type Values Removed Values Added
Description Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote attacker sends a specially crafted request to the product's web service, arbitrary code may be executed when the product is configured to run pop3wallpasswd with grdnwww user privilege.
Weaknesses CWE-121
References
Metrics cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Canon Marketing Japan Guardianwall Mail Security Cloud (saas Version) Guardianwall Mailsuite (on-premises Version)
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-05-13T10:49:48.622Z

Reserved: 2026-05-11T00:11:34.095Z

Link: CVE-2026-32661

cve-icon Vulnrichment

Updated: 2026-05-13T10:48:17.002Z

cve-icon NVD

Status : Deferred

Published: 2026-05-13T06:16:14.253

Modified: 2026-05-13T15:47:10.327

Link: CVE-2026-32661

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T10:34:50Z

Weaknesses