CVE-2026-2743

Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (LFT). This issue affects SeppMail: 15.0.2.1 and before
Configurations

Configuration 1 (hide)

cpe:2.3:a:seppmail:seppmail:*:*:*:*:*:*:*:*

History

19 May 2026, 20:16

Type Values Removed Values Added
References () https://labs.infoguard.ch/posts/seppmail_secure_e-mail_gateway_rce_vulnerabilities_cve-2026-2743_cve-2026-7864_cve-2026-44127_cve-2026-44128/ - () https://labs.infoguard.ch/posts/seppmail_secure_e-mail_gateway_rce_vulnerabilities_cve-2026-2743_cve-2026-7864_cve-2026-44127_cve-2026-44128/ -

18 May 2026, 17:16

Type Values Removed Values Added
References
  • {'url': 'https://labs.infoguard.ch/advisories/seppmail', 'tags': ['Third Party Advisory'], 'source': 'vulnerability@ncsc.ch'}
  • () https://labs.infoguard.ch/posts/seppmail_secure_e-mail_gateway_rce_vulnerabilities_cve-2026-2743_cve-2026-7864_cve-2026-44127_cve-2026-44128/ -
Summary (en) Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (LFT). This issue affects SeppMail: 15.0.2.1 and before (en) Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (LFT). This issue affects SeppMail: 15.0.2.1 and before

09 Mar 2026, 18:31

Type Values Removed Values Added
References () https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html - () https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html - Release Notes
References () https://labs.infoguard.ch/advisories/seppmail - () https://labs.infoguard.ch/advisories/seppmail - Third Party Advisory
Summary
  • (es) Escritura arbitraria de archivos mediante carga por salto de ruta que lleva a ejecución remota de código en la interfaz web de usuario de SeppMail. La característica afectada es la transferencia de archivos grandes (LFT). Este problema afecta a SeppMail: 15.0.2.1 y versiones anteriores.
First Time Seppmail
Seppmail seppmail
CPE cpe:2.3:a:seppmail:seppmail:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

05 Mar 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-05 07:16

Updated : 2026-06-17 10:31


NVD link : CVE-2026-2743

Mitre link : CVE-2026-2743

CVE.ORG link : CVE-2026-2743


JSON object : View

Products Affected

seppmail

  • seppmail
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-434

Unrestricted Upload of File with Dangerous Type