JVN#35567473
GUARDIANWALL MailSuite vulnerable to stack-based buffer overflow
Critical
Overview
GUARDIANWALL MailSuite provided by Canon Marketing Japan Inc. contains a stack-based buffer overflow vulnerability.
Products Affected
- GUARDIANWALL MailSuite (On-premises version) Ver 1.4.00 to Ver 2.4.26
- GUARDIANWALL Mail Security Cloud (SaaS version) versions before the maintenance on April 30, 2026
Description
GUARDIANWALL MailSuite provided by Canon Marketing Japan Inc. contains the following vulnerability.
- Stack-based buffer overflow in
pop3wallpasswdcommand (CWE-121)- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 9.3
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Base Score 9.8
- CVE-2026-32661
- This can be exploited only when the product is configured to run
pop3wallpasswdwithgrdnwwwuser privilege
Impact
If a remote attacker sends a specially crafted request to the product's web service, arbitrary code may be executed.
Solution
Apply the patch
Apply all the patches provided by the developer.
Note that, GUARDIANWALL Mail Security Cloud (SaaS version) has already been fixed with April 30, 2026 updates.
Apply the Workaround
The developer recommends the users to follow the workaround until applying the patch.
For more details, refer to the information provided by the developer.
Vendor Status
| Vendor | Status | Last Update | Vendor Notes |
|---|---|---|---|
| Canon Marketing Japan Inc. | Vulnerable | 2026/05/13 | Canon Marketing Japan Inc. website |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Canon Marketing Japan Inc. reported this vulnerability to JPCERT/CC to notify users of its solution through JVN. JPCERT/CC and Canon Marketing Japan Inc. coordinated under the Information Security Early Warning Partnership.
Other Information
| JPCERT Alert |
JPCERT-AT-2026-0013 Alert Regarding Stack-based Buffer Overflow Vulnerability (CVE-2026-32661) in GUARDIANWALL MailSuite (Text in Japanese) |
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-32661 |
| JVN iPedia |
JVNDB-2026-000072 |
Update History
- 2026/05/13
- Information under the section "Other Information" was updated
- 2026/05/13
- Canon Marketing Japan Inc. update status