CVE-2026-84830
- EPSS 1.07%
- Veröffentlicht 03.09.2026 08:45:42
- Zuletzt bearbeitet 03.09.2026 18:14:11
SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges.
CVE-2026-84832
- EPSS 0.65%
- Veröffentlicht 03.09.2026 08:45:08
- Zuletzt bearbeitet 04.09.2026 17:17:01
SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.
CVE-2026-84831
- EPSS 0.45%
- Veröffentlicht 03.09.2026 08:43:46
- Zuletzt bearbeitet 03.09.2026 18:14:11
SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected function...
CVE-2026-9592
- EPSS 0.15%
- Veröffentlicht 17.07.2026 13:51:54
- Zuletzt bearbeitet 17.07.2026 18:11:59
SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header.
CVE-2026-8811
- EPSS 0.32%
- Veröffentlicht 18.06.2026 09:05:46
- Zuletzt bearbeitet 22.06.2026 19:45:16
SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An attacker can exploit this to create new files outside the intended directory, potentially placing files in web-accessible locations.
CVE-2026-44126
- EPSS 0.47%
- Veröffentlicht 08.05.2026 13:15:52
- Zuletzt bearbeitet 18.05.2026 17:16:32
SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI and may allow unauthenticated remote attackers to execute code via a crafted serialized object.
CVE-2026-44125
- EPSS 0.39%
- Veröffentlicht 08.05.2026 13:15:07
- Zuletzt bearbeitet 18.05.2026 17:16:32
SEPPmail Secure Email Gateway before version 15.0.4 fails to enforce authorization checks for multiple endpoints in the new GINA UI, allowing unauthenticated remote attackers to access functionality that should require a valid session.
CVE-2026-44129
- EPSS 0.54%
- Veröffentlicht 08.05.2026 13:14:36
- Zuletzt bearbeitet 18.05.2026 17:16:33
SEPPmail Secure Email Gateway before version 15.0.4 contains a server-side template injection vulnerability in the new GINA UI because an endpoint accepts attacker-controlled template, allowing remote attackers to execute arbitrary template expressio...
CVE-2026-44128
- EPSS 0.85%
- Veröffentlicht 08.05.2026 13:13:46
- Zuletzt bearbeitet 18.05.2026 17:16:32
SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code execution in the new GINA UI because an endpoint passes attacker-controlled input from a parameter to Perl's eval.
CVE-2026-44127
- EPSS 15.65%
- Veröffentlicht 08.05.2026 13:13:05
- Zuletzt bearbeitet 18.05.2026 17:16:32
SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal vulnerability in the identifier parameter of /api.app/attachment/preview that allows remote attackers to read arbitrary local files and trigger deletion of...