CVE-2026-7864 PUBLISHED

Exposure of Sensitive Information to an Unauthorized Actor

Assigner: NCSC.ch
Reserved: 05.05.2026 Published: 08.05.2026 Updated: 08.05.2026

SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain sensitive system information.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor SEPPmail AG
Product Secure Email Gateway
Versions Default: unaffected
  • affected from 0 to 15.0.4 (excl.)

References

Problem Types

  • CWE-497 Exposure of sensitive system information to an unauthorized control sphere CWE

Impacts

  • CAPEC-37 Retrieve Embedded Sensitive Data