CVE-2026-44128
Unauthenticated Remote Code Execution
CVSS Score
0.0
EPSS Score
0.4%
EPSS Percentile
63th
SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code execution in the new GINA UI because an endpoint passes attacker-controlled input from a parameter to Perl's eval.
| CWE | CWE-95 |
| Vendor | seppmail ag |
| Product | secure email gateway |
| Published | May 8, 2026 |
| Last Updated | May 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for seppmail ag secure email gateway
Be the first to know when new unknown vulnerabilities affecting seppmail ag secure email gateway are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
SEPPmail AG / Secure Email Gateway
0 < 15.0.2.1
References
Credits
Dario Weiss of InfoGuard Labs