SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain sensitive system information.
CVSS
No CVSS.
References
Configurations
No configuration.
History
18 May 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
08 May 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-08 14:16
Updated : 2026-05-18 17:16
NVD link : CVE-2026-7864
Mitre link : CVE-2026-7864
CVE.ORG link : CVE-2026-7864
JSON object : View
Products Affected
No product.
CWE
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
