GHSA-gh4w-5vrf-hhcgHigh
SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal...
🔗 CVE IDs covered (1)
📋 Description
SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal vulnerability in the identifier parameter of /api.app/attachment/preview that allows remote attackers to read arbitrary local files and trigger deletion of files in the targeted directory with the privileges of the api.app process.
🔗 References (4)
- https://nvd.nist.gov/vuln/detail/CVE-2026-44127
- https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html#security
- https://labs.infoguard.ch/posts/seppmail_secure_e-mail_gateway_rce_vulnerabilities_cve-2026-2743_cve-2026-7864_cve-2026-44127_cve-2026-44128
- https://github.com/advisories/GHSA-gh4w-5vrf-hhcg