SEPPmail Secure Email Gateway Missing Authorization Vulnerability in GINA UI

Vulnerability

A vulnerability exists in SEPPmail Secure Email Gateway versions prior to 15.0.4, where authorization checks are not properly enforced for several endpoints in the GINA user interface. This flaw allows unauthenticated remote attackers to access features that should require a valid session.

Impact

Exploitation of this vulnerability could lead to unauthorized access to functionalities within the GINA user interface, potentially allowing attackers to perform actions or access information that should be restricted.

Remediation

Users can update to SEPPmail Secure Email Gateway version 15.0.4 or later to address this vulnerability.

Added: May 8, 2026, 2:46 PM
Updated: May 8, 2026, 2:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
5.0
exploitability
7.6
remediation
7.7
relevance
7.8
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.