CVE-2026-44129

HIGH

SEPPmail Secure Email Gateway - Server-Side Template Injection

Title source: manual
STIX 2.1

Description

SEPPmail Secure Email Gateway before version 15.0.4 contains a server-side template injection vulnerability in the new GINA UI because an endpoint accepts attacker-controlled template, allowing remote attackers to execute arbitrary template expressions and potentially achieve remote code execution depending on the enabled template plugins.

Scores

CVSS v4 8.3
EPSS 0.0053
EPSS Percentile 40.7%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1336
Status published
Products (1)
SEPPmail AG/Secure Email Gateway < 15.0.4
Published May 08, 2026
Tracked Since May 08, 2026