Junglewise Threat Intelligence

CVE-2026-2743: SeppMail Secure E-Mail Gateway RCE via path traversal in LFT

CVE-2026-2743 · Severity: critical · CVSS 9.8 · Published 2026-03-05

Executive brief

SeppMail Secure E-Mail Gateway, a specialized appliance used for encrypted corporate email communication, contains a critical vulnerability in its Large File Transfer (LFT) feature. An attacker can exploit this flaw to remotely take control of the appliance without needing a password. Successful exploitation allows an attacker to intercept, read, or modify all email traffic passing through the gateway, potentially leading to massive data breaches and long-term unauthorized access to corporate communications.

Technical details

A path traversal vulnerability exists in the 'handle_request' function of the '/v1/file.app' endpoint within the Large File Transfer (LFT) component. The application fails to sanitize the 'file' parameter in the JSON payload during chunked uploads, allowing an attacker to write arbitrary files as the 'nobody' user. Because the 'nobody' user has write permissions to '/etc/syslog.conf' on the OpenBSD-based appliance, an attacker can overwrite the syslog configuration to pipe log messages into a Perl-based reverse shell. Execution is triggered when 'newsyslog' rotates logs and sends a SIGHUP to 'syslogd', which can be forced by bloating log files through web requests. This results in full remote code execution. The issue is fixed in version 15.0.4.

Affected products

  • SeppMail Secure E-Mail Gateway Up to and including 15.0.2.1

Timeline

  • 2026-03-05: disclosed
  • 2026-03-05: advisory
  • 2026-04-24: patched: Fixed in version 15.0.4

References