Executive brief
SEPPmail Secure Email Gateway, a solution used to encrypt and manage corporate email traffic, contains a security flaw in its web-based user interface. This vulnerability allows an unauthorized person to access sensitive functions and data that should normally require a password. An attacker could exploit this to bypass security controls, potentially compromising the confidentiality and integrity of the email system.
Technical details
A missing authorization vulnerability (CWE-862) exists in the GINA V2 UI component of the SEPPmail Secure Email Gateway. The application fails to perform sufficient permission checks on several API endpoints, allowing unauthenticated remote attackers to interact with backend functionality that is intended to be restricted to valid, authenticated sessions. This flaw was identified alongside several other critical vulnerabilities in the GINA interface, including remote code execution and local file inclusion. Attackers can exploit this lack of authorization to bypass security boundaries and potentially access sensitive email data or administrative functions. The issue is resolved in version 15.0.4.
Affected products
- SEPPmail Secure Email Gateway before 15.0.4
Timeline
- 2026-04-24: patched: Fixed in version 15.0.4 Bugfix Release
- 2026-05-08: advisory: Initial NVD publication
- 2026-05-18: disclosed: Detailed technical advisory released by InfoGuard Labs