SEPPmail Secure Email Gateway Unauthenticated Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in SEPPmail Secure Email Gateway versions prior to 15.0.2.1. This vulnerability arises in the new GINA user interface, where an endpoint improperly handles attacker-controlled input by passing it from a parameter to Perl's eval function, allowing for the execution of arbitrary code.

Impact

Exploitation of this vulnerability allows for unauthenticated remote code execution on the server where SEPPmail Secure Email Gateway is running.

Remediation

Users can update to SEPPmail Secure Email Gateway version 15.0.2.1 or later, where this vulnerability has been fixed.

Added: May 8, 2026, 2:42 PM
Updated: May 8, 2026, 2:42 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
7.5
exploitability
7.6
remediation
7.7
relevance
7.8
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.