Description
SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header.
Published: 2026-07-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SEPPmail Secure Email Gateway and SEPPmail Cloud expose session tokens in the URL and HTTP headers before version 15.0.4.2, allowing an attacker to replay and hijack a user session within the GINA web portal. The vulnerability is an instance of CWE‑598, where an insecure mechanism inadvertently reveals sensitive information. An attacker who gains access to the token can impersonate the legitimate user, potentially accessing confidential data or controlling the account.

Affected Systems

SEPPmail Secure Email Gateway and SEPPmail Cloud customers running any version older than 15.0.4.2 are vulnerable. The issue affects the GINA web portal component of both products.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, yet the EPSS score is below 1% and the vulnerability is not currently listed in the CISA KEV catalog, suggesting limited publicly known exploitation. The attack vector is likely a network attacker able to capture HTTP traffic or view browser URLs, which then can replay the disclosed session token. Exploitation requires intercepting or observing the HTTP request containing the token and re‑sending it to gain unauthorized access.

Generated by OpenCVE AI on July 31, 2026 at 00:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SEPPmail Secure Email Gateway and SEPPmail Cloud to version 15.0.4.2 or later to eliminate session token disclosure.
  • Ensure that all traffic to the GINA web portal is served over HTTPS and that session tokens are not appended to URLs or exposed in headers.
  • Configure the application to use HTTP‑only secure cookies for session tokens and eliminate their inclusion in URLs.

Generated by OpenCVE AI on July 31, 2026 at 00:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Seppmail
Seppmail seppmail Secure Email Gateway
Vendors & Products Seppmail
Seppmail seppmail Secure Email Gateway

Fri, 17 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Description SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header.
Title Sensitive Information Disclosure in HTTP header
Weaknesses CWE-598
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:U'}


Subscriptions

Seppmail Seppmail Secure Email Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-07-17T15:24:58.669Z

Reserved: 2026-05-26T13:55:29.125Z

Link: CVE-2026-9592

cve-icon Vulnrichment

Updated: 2026-07-17T15:24:50.336Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T00:30:18Z

Weaknesses
  • CWE-598

    Use of HTTP Request With Sensitive Query String