CRITICAL🇵🇱 Wersja polska

CVE-2026-27441

CVSS 9.5v4.0pub. 2026-03-04upd. 2026-03-05

SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS command execution.

🤖 AI Analysis
How it works

The command injection vulnerability (CWE-78) consists of insufficient filtering or neutralization of input data passed as a PDF encryption password. An attacker can embed specially prepared characters or sequences of system commands in the password field, which are then executed by the operating system in the context of the email gateway process. The attack is possible remotely, without authentication, which significantly increases its severity.

Impact

An attacker can execute arbitrary commands at the operating system level on the server, which may lead to complete takeover of the device, leakage of processed email messages, and violation of integrity and confidentiality of the mail infrastructure.

Mitigation & patch

SEPPmail Secure Email Gateway should be updated to version 15.0.1 or later as soon as possible. Detailed information about the update is available in the manufacturer's release notes at: https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html#seppmail-vulnerability-disclosure

Who is affected

SEPPmail Secure Email Gateway in versions prior to 15.0.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Seppmail

    APP
    Seppmail
    < 15.0.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2026-2743CRITICAL10.0PL ✓same product

RCE przez path traversal i zapis pliku w SeppMail User Web Interface

CVE-2026-27442CRITICAL9.3PL ✓same product

SEPPmail Secure Email Gateway — path traversal w interfejsie GINA

CVE-2026-27444HIGH7.8same product

SEPPmail Secure Email Gateway before version 15.0.1 incorrectly interprets email addresses in the email header...

CVE-2026-27443HIGH8.2same product

SEPPmail Secure Email Gateway before version 15.0.1 does not properly sanitize the headers from S/MIME protect...

CVE-2026-2748HIGH7.8same product

SEPPmail Secure Email Gateway before version 15.0.1 improperly validates S/MIME certificates issued for email ...