Executive brief
SEPPmail Secure Email Gateway, a solution used for encrypting and managing corporate email communications, contains a critical vulnerability in its web interface. An unauthenticated remote attacker can exploit this flaw to execute arbitrary commands on the appliance. This could lead to a total system takeover, allowing attackers to intercept sensitive emails, disrupt mail flow, or gain a foothold in the corporate network.
Technical details
SEPPmail Secure Email Gateway before version 15.0.4 is vulnerable to insecure deserialization (CWE-502). The flaw exists within the 'GINA' web interface (specifically the newer GINA UI), where the application fails to properly validate or sanitize serialized objects provided by users. An unauthenticated remote attacker can exploit this by sending a specially crafted serialized object to the affected endpoint. Successful exploitation allows for arbitrary code execution with the privileges of the web service user, potentially leading to full appliance compromise. The issue was addressed in version 15.0.4 and subsequent hotfixes.
Affected products
- SEPPmail Secure Email Gateway before 15.0.4
Timeline
- 2026-04-24: patched: Fixed in version 15.0.4 Bugfix Release
- 2026-05-08: advisory: Initial NVD publication
- 2026-05-18: disclosed: Detailed technical advisory released by InfoGuard Labs