PT-2026-22888 · Seppmail · Seppmail Secure Email Gateway

Andris Suter-Dörig

+2

·

Published

2026-03-04

·

Updated

2026-03-06

·

CVE-2026-27442

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions SEPPmail Secure Email Gateway versions prior to 15.0.1
Description The GINA web interface does not properly validate attachment filenames within GINA-encrypted emails. This allows an attacker to potentially access files on the gateway. The issue resides in the handling of filenames during the decryption process. The vulnerable component is the GINA web interface.
Recommendations Update SEPPmail Secure Email Gateway to version 15.0.1 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27442

Affected Products

Seppmail Secure Email Gateway