Executive brief
SEPPmail Secure Email Gateway, an appliance used for encrypting and managing corporate email, contains a security flaw in its web interface. An unauthenticated attacker can exploit this to read sensitive system files or delete files on the device. This could lead to the exposure of confidential configuration data or cause service disruptions by removing critical application files.
Technical details
A path traversal vulnerability exists in the 'identifier' parameter of the /api.app/attachment/preview endpoint within the GINA v2 component of SEPPmail Secure Email Gateway. The application fails to properly sanitize user-supplied input, allowing an unauthenticated remote attacker to use directory traversal sequences (e.g., ../) to access files outside of the intended directory. An attacker can exploit this to read arbitrary local files or trigger the deletion of files within the targeted directory with the privileges of the 'api.app' process. This vulnerability was addressed in version 15.0.4.
Affected products
- SEPPmail Secure Email Gateway before 15.0.4
Timeline
- 2026-04-24: patched: Fixed in version 15.0.4 Bugfix Release
- 2026-05-08: disclosed: Initial NVD publication
- 2026-05-18: advisory: Detailed technical advisory released by InfoGuard Labs