SEP sesam Backup Server: unauthenticated remote root code execution via template injection in the executeSql endpoint

An unauthenticated attacker who reaches port 11401 runs arbitrary code as root on the backup server with a single HTTP request, because the REST API runs without authentication by default and compiles a RYTHM template expression to Java bytecode.

Advisory ID: TP-2026-073
Product: SEP sesam Backup Server (German enterprise backup and recovery software)
Vulnerability type: Server-side template injection leading to remote code execution (CWE-1336)
Further weaknesses: missing authentication (CWE-306), execution with unnecessary privileges (CWE-250)
CVE: pending (MITRE CNA-LR)
CVSS 3.1: 10.0 (Critical) · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected versions: 5.2.0-26 (Artemis V6) and earlier
Fixed in: fixed by the vendor (SEP ticket #36822; exact version to be confirmed)
Reported: 03 September 2026

Summary

SEP sesam is enterprise backup software by SEP AG. Its REST API listens on TCP 11401 and is reachable without authentication on every default installation, because the installer sets authEnabled=false. The /sep/api/v2/cli/executeSql endpoint accepts a caller-controlled template parameter; with format=RYTHM it is handed to the Rythm template engine, which compiles the string to Java bytecode and executes it. Because all SEP sesam services run as root, a single unauthenticated HTTP request yields remote root code execution. The vendor reproduced and confirmed the finding (ticket #36822) and has provided a fix.

Root cause

The installer writes authEnabled=false to sm.ini, and GUIServerParam.authEnabled defaults to false (sm_db_update.ini:462).
When the flag is false, LoginServiceImpl.authenticate() calls forceCreateAndAuthenticateAdmin() and grants every request administrator access with no credentials.
CliServiceImpl.executeSql() passes the caller-controlled template parameter with format=RYTHM to RendererServiceImpl.render() (line 297), which calls RythmEngine.render().
Rythm compiles the template string to Java bytecode and executes it, so arbitrary Java code runs.
The systemd unit sepsesam.service leaves User= and Group= commented out, so the REST API runs as root and the code execution therefore holds root privileges.

Proof of Concept

Schematically: a single HTTP request, no authentication.

POST /sep/api/v2/cli/executeSql   (TCP 11401)
Content-Type: application/json; base64
{"query":"SELECT 1","format":"RYTHM","template":"<Rythm expression>"}

Because authEnabled is false out of the box, the REST API grants the call administrator rights. The RYTHM template expression is compiled to Java bytecode and executed; since all services run as root, the result is root code execution. The copy-paste execution payload is withheld.

Impact

  • Root code execution on the backup server through a single unauthenticated request.
  • Access to all backed-up data of every client and to stored backup credentials (S3 keys, SSH keys, database passwords).
  • Deletion or encryption of all backups as preparation for a ransomware attack.
  • Lateral movement into every system protected by SEP sesam using the stolen credentials.

References

Is Something Like This in Your Software?

Our team found this vulnerability during its work. Have your applications tested by the same specialists, with a penetration test from turingpoint.