216.73.216.226

CVE-2026-44127

· Published 08/05/2026 14:16 · Modified 08/05/2026 15:51

Labels: CVE-2026-44127 2026-05-08CVE-2026-44127CWE-73[email protected]

Essential information

Published
08/05/2026 14:16
Modified
08/05/2026 15:51
Author
Creator
CVSS
8.8 HIGH (v3) 8.8 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal vulnerability in the identifier parameter of /api.app/attachment/preview that allows remote attackers to read arbitrary local files and trigger deletion of files in the targeted directory with the privileges of the api.app process.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
seppmail / seppmail secure email gateway cpe:2.3:a:seppmail:seppmail_secure_email_gateway:<15.0.4:*:*:*:*:*:*:*

References