Description
SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges.
Published: 2026-09-03
Score: 8.6 High
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a command injection flaw in the privileged configuration handling of SEPPmail Secure Email Gateway. When an authenticated administrator submits configuration data, the system fails to properly sanitize input, allowing crafted strings to be interpreted as operating‑system commands. Successful exploitation enables the attacker to run arbitrary commands with the privileges of the gateway process, leading to full control over the affected device and any connected resources.

Affected Systems

SEPPmail AG’s Secure Email Gateway products are affected, specifically all releases prior to version 15.0.7. Users running any 15.0.x build below 15.0.7 should verify their deployment.

Risk and Exploitability

The CVSS score of 8.6 reflects a high severity and the absence of mitigation controls in normal operation. The EPSS score is 1%, indicating a low but non‑zero likelihood that this vulnerability is being actively exploited. The flaw is known and requires an authenticated administrator, meaning that an insider threat or compromised admin credentials can trigger the exploit. The issue is not listed in CISA’s KEV catalog, yet its impact and the ability for an attacker to execute arbitrary commands with elevated privileges make it a critical risk for any exposed or compromised administrator accounts.

Generated by OpenCVE AI on September 3, 2026 at 14:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SEPPmail Secure Email Gateway to version 15.0.7 or later to remove the command injection flaw.
  • Restrict the privileged configuration interface to trusted administrators and enforce strong multi‑factor authentication to reduce the risk of credential compromise.
  • Enable logging and monitoring of configuration changes, and conduct regular audits to detect unauthorized attempts to inject commands.

Generated by OpenCVE AI on September 3, 2026 at 14:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Seppmail
Seppmail secure Email Gateway
Vendors & Products Seppmail
Seppmail secure Email Gateway

Thu, 03 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges.
Title OS command injection in privileged configuration handling
Weaknesses CWE-269
CWE-78
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Seppmail Secure Email Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-09-03T12:32:36.198Z

Reserved: 2026-09-02T11:31:38.548Z

Link: CVE-2026-84830

cve-icon Vulnrichment

Updated: 2026-09-03T12:32:31.291Z

cve-icon NVD

Status : Deferred

Published: 2026-09-03T13:06:18.593

Modified: 2026-09-03T18:14:11.063

Link: CVE-2026-84830

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:30:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')