Executive brief
SEPPmail Secure Email Gateway and SEPPmail Cloud are used to secure corporate email communications. A vulnerability in the GINA web portal allows unauthorized individuals to see and reuse active user session tokens because they are improperly exposed in web addresses and headers. This could allow an attacker to hijack a user's session, potentially gaining access to sensitive encrypted emails and private communications.
Technical details
A session hijacking vulnerability exists in the GINA web portal of SEPPmail Secure Email Gateway and SEPPmail Cloud. The root cause is the improper disclosure of session tokens within the URL (query strings) and HTTP headers, violating secure session management practices (CWE-598). An attacker with access to the network traffic or browser history could capture these tokens to replay or hijack active user sessions. This allows for unauthorized access to the web portal without requiring credentials. The issue is resolved in version 15.0.4.2 and later.
Affected products
- SEPPmail Secure Email Gateway before 15.0.4.2
- SEPPmail SEPPmail Cloud before 15.0.4.2
Timeline
- 2026-07-17: advisory: NVD publication date
- 2026-05-11: patched: Approximate patch timeframe based on release notes for 15.0.4.3 and 15.0.5