GHSA-qwq6-r6c6-68jrCritical
SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code...
🔗 CVE IDs covered (1)
📋 Description
SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code execution in the new GINA UI because an endpoint passes attacker-controlled input from a parameter to Perl's eval.
🔗 References (4)
- https://nvd.nist.gov/vuln/detail/CVE-2026-44128
- https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html#security
- https://labs.infoguard.ch/posts/seppmail_secure_e-mail_gateway_rce_vulnerabilities_cve-2026-2743_cve-2026-7864_cve-2026-44127_cve-2026-44128
- https://github.com/advisories/GHSA-qwq6-r6c6-68jr