CVE-2026-2747 PUBLISHED

PGP Mixed Plaintext and Encrypted Content

Assigner: NCSC.ch
Reserved: 19.02.2026 Published: 04.03.2026 Updated: 04.03.2026

SEPPmail Secure Email Gateway before version 15.0.1 decrypts inline PGP messages without isolating them from surrounding unencrypted content, allowing exposure of sensitive information to an unauthorized actor.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor SEPPmail
Product Secure Email Gateway
Versions Default: unaffected
  • affected from 0 to 15.0.1 (excl.)

Credits

  • Andris Suter-Dörig finder
  • Matteo Scarlata coordinator
  • Kenny Paterson coordinator

References

Problem Types

  • CWE-200 Exposure of Sensitive Information to an Unauthorized Actor CWE

Impacts

  • CAPEC-116 Excavation