GUARDIANWALL MailSuite provided by Canon Marketing Japan Inc. contains a stack-based buffer overflow vulnerability.
- GUARDIANWALL MailSuite (On-premises version) Ver 1.4.00 to Ver 2.4.26
- GUARDIANWALL Mail Security Cloud (SaaS version) versions before the maintenance on April 30, 2026
GUARDIANWALL MailSuite provided by Canon Marketing Japan Inc. contains the following vulnerability.
- Stack-based buffer overflow in
pop3wallpasswdcommand (CWE-121)- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 9.3
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Base Score 9.8
- CVE-2026-32661
- This can be exploited only when the product is configured to run
pop3wallpasswdwithgrdnwwwuser privilege
If a remote attacker sends a specially crafted request to the product's web service, arbitrary code may be executed.
Apply the patch
Apply all the patches provided by the developer.
Note that, GUARDIANWALL Mail Security Cloud (SaaS version) has already been fixed with April 30, 2026 updates.
Apply the Workaround
The developer recommends the users to follow the workaround until applying the patch.
For more details, refer to the information provided by the developer.
| Vendor | Status | Last Update | Vendor Notes |
|---|---|---|---|
| Canon Marketing Japan Inc. | Vulnerable | 2026/05/13 | Canon Marketing Japan Inc. website |
Canon Marketing Japan Inc. reported this vulnerability to JPCERT/CC to notify users of its solution through JVN. JPCERT/CC and Canon Marketing Japan Inc. coordinated under the Information Security Early Warning Partnership.
| JPCERT Alert |
JPCERT-AT-2026-0013 Alert Regarding Stack-based Buffer Overflow Vulnerability (CVE-2026-32661) in GUARDIANWALL MailSuite (Text in Japanese) |
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-32661 |
| JVN iPedia |
JVNDB-2026-000072 |