Junglewise Threat Intelligence

CVE-2026-7864: SEPPmail Secure Email Gateway information disclosure in GINA UI

CVE-2026-7864 · Severity: info · CVSS 6.9 · Published 2026-05-08

Executive brief

SEPPmail Secure Email Gateway, a solution used for encrypting and securing corporate email communications, contains a vulnerability in its GINA web interface. An unauthenticated remote attacker can access a specific web endpoint to view the server's environment variables. This exposure could reveal sensitive system configuration details, potentially aiding in further targeted attacks against the organization's email infrastructure.

Technical details

The vulnerability is classified as an Information Exposure (CWE-497) within the 'GINA V2' web interface component of the SEPPmail Secure Email Gateway. An unauthenticated remote attacker can access a specific, unprotected endpoint that leaks server-side environment variables. These variables may contain sensitive system paths, configuration parameters, or internal metadata that provide an attacker with a footprint of the appliance's internal environment. The issue is resolved in version 15.0.4. This vulnerability was identified alongside several more critical flaws (such as RCE and LFI) in the same component.

Affected products

  • SEPPmail Secure Email Gateway before 15.0.4

Timeline

  • 2026-04-24: patched: Fixed in version 15.0.4 Bugfix Release
  • 2026-05-08: advisory: Initial CVE publication
  • 2026-05-18: disclosed: Technical details published by InfoGuard Labs

References