SEPPmail Secure Email Gateway Unauthenticated Path Traversal Vulnerability Allowing Arbitrary File Read and Deletion

Vulnerability

A path traversal vulnerability has been identified in SEPPmail Secure Email Gateway versions prior to 15.0.4. This vulnerability allows remote attackers to access arbitrary local files and delete files in the targeted directory, using the privileges of the api.app process. The issue arises in the identifier parameter of the /api.app/attachment/preview endpoint, where improper validation allows for unauthorized file manipulation.

Impact

Exploitation of this vulnerability could lead to unauthorized access and deletion of files on the server, potentially causing data loss or disruption of service.

Remediation

Users can update to SEPPmail Secure Email Gateway version 15.0.4 or later to address this vulnerability.

Added: May 8, 2026, 2:43 PM
Updated: May 8, 2026, 2:43 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
5.0
exploitability
8.3
remediation
7.7
relevance
7.8
threat
0.0
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.