CVE-2026-8811 PUBLISHED

Path traversal in PDF generation module

Assigner: NCSC.ch
Reserved: 18.05.2026 Published: 18.06.2026 Updated: 18.06.2026

SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An attacker can exploit this to create new files outside the intended directory, potentially placing files in web-accessible locations.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L
CVSS Score: 7.1

Product Status

Vendor SEPPmail AG
Product Secure Email Gateway
Versions Default: unaffected
  • affected from 0 to 15.0.5 (excl.)

Credits

  • Andris Suter-Dörig (ETH Zürich, Applied Crypto Group) finder
  • Olivier Becker (InfoGuard AG) finder

References

Problem Types

  • CWE-22 CWE

Impacts

  • CAPEC-126 Path Traversal