PT-2026-29703 · Seppmail · Seppmail Secure Email Gateway

Andris Suter-Dörig

+2

·

Published

2026-04-02

·

Updated

2026-04-02

·

CVE-2026-29139

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SEPPmail Secure Email Gateway versions prior to 15.0.3
Description SEPPmail Secure Email Gateway versions prior to 15.0.3 are susceptible to account takeover. This is due to a flaw in the GINA account initialization process, which can be exploited to reset victim account passwords.
Recommendations Update SEPPmail Secure Email Gateway to version 15.0.3 or later.

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-29139

Affected Products

Seppmail Secure Email Gateway