CVE-2026-44126 PUBLISHED

Insecure deserialization

Assigner: NCSC.ch
Reserved: 05.05.2026 Published: 08.05.2026 Updated: 08.05.2026

SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI and may allow unauthenticated remote attackers to execute code via a crafted serialized object.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.2

Product Status

Vendor SEPPmail AG
Product Secure Email Gateway
Versions Default: unaffected
  • affected from 0 to 15.0.4 (excl.)

References

Problem Types

  • CWE-502 Deserialization of untrusted data CWE

Impacts

  • CAPEC-586 Object Injection