CVE-2026-7864
Exposure of Sensitive Information to an Unauthorized Actor
CVSS Score
0.0
EPSS Score
0.2%
EPSS Percentile
41th
SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain sensitive system information.
| CWE | CWE-497 |
| Vendor | seppmail ag |
| Product | secure email gateway |
| Published | May 8, 2026 |
| Last Updated | May 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for seppmail ag secure email gateway
Be the first to know when new unknown vulnerabilities affecting seppmail ag secure email gateway are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
SEPPmail AG / Secure Email Gateway
0 < 15.0.4
References
Credits
Dario Weiss of InfoGuard Labs