← Back to browse · API

CVE-2026-44127

Severity
HIGH
CVSS
8.8
EPSS
0.15653
Risk score
40.68
CISA KEV
No
PoC
No
Published
2026-05-08
Modified
2026-05-18
First seen
2026-08-07
Aliases
EUVD-2026-28587, GHSA-GH4W-5VRF-HHCG
Products
SEPPmail AG:Secure Email Gateway 0 <15.0.4
Sources
euvd EUVD-2026-28587

Description

SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal vulnerability in the identifier parameter of /api.app/attachment/preview that allows remote attackers to read arbitrary local files and trigger deletion of files in the targeted directory with the privileges of the api.app process.

References