Junglewise Threat Intelligence

CVE-2026-44128: SEPPmail Secure Email Gateway RCE in GINA UI

CVE-2026-44128 · Severity: info · CVSS 9.3 · Published 2026-05-08

Executive brief

SEPPmail Secure Email Gateway, a solution used for encrypting and securing corporate email communications, contains a critical vulnerability in its GINA web interface. An unauthenticated attacker can remotely execute arbitrary commands on the gateway, potentially leading to a complete system takeover. This would allow an attacker to intercept, read, or modify sensitive email traffic and gain a persistent foothold within the corporate network.

Technical details

A critical remote code execution (RCE) vulnerability exists in the GINA V2 UI component of the SEPPmail Secure Email Gateway. The flaw is categorized as Eval Injection (CWE-95), where a specific web endpoint fails to sanitize user-supplied parameters before passing them to Perl's 'eval' function. An unauthenticated remote attacker can exploit this by sending a specially crafted network request to the vulnerable endpoint. Successful exploitation allows the attacker to execute arbitrary code with the privileges of the web service user, leading to full appliance compromise. The issue was addressed in version 15.0.2.1.

Affected products

  • SEPPmail Secure Email Gateway before 15.0.2.1

Timeline

  • 2026-05-08: disclosed
  • 2026-05-08: advisory: NVD publication date
  • 2026-05-18: other: Detailed technical write-up published by InfoGuard Labs

References