NUMail, a mail application developed by Green-Computing, contains a critical OS Command Injection vulnerability tracked as CVE-2026-82082. The flaw allows unauthenticated remote attackers to inject and execute arbitrary OS commands directly on the server. No authentication is required to exploit this vulnerability, making it highly dangerous and easily exploitable. The vulnerability was reported via Taiwan's TWCERT/CC and published on NVD. Successful exploitation could lead to full server compromise, unauthorized data access, and potential lateral movement within the network. The unauthenticated nature of the attack vector significantly raises the risk and criticality of this vulnerability.