Impact
SEPPmail Secure Email Gateway prior to version 15.0.7 creates a fully privileged session before multi‑factor authentication is completed. An attacker who knows the password for an MFA‑required but unenrolled account can log in and access protected functionality without providing a second factor. This flaw allows unauthorized privileged access, potentially compromising the confidentiality, integrity, and availability of the email gateway system.
Affected Systems
The vulnerability affects SEPPmail AG’s Secure Email Gateway product, specifically all releases before 15.0.7. The issue arises in any environment where MFA is required but not fully enforced at session start.
Risk and Exploitability
The CVSS score of 7.7 classifies the bug as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that documented exploitation may not yet exist. Nonetheless, the ability to bypass MFA and gain privileged access represents a serious threat. The likely attack vector is remote, via normal login credentials; an attacker must first obtain or guess a valid username and password for a user account that has MFA enabled but not yet enrolled. Once authenticated, the system grants full privileges without the second factor.
OpenCVE Enrichment