← Vulnerability feed

Vulnerability record · CVE-2026-29141 · published 2 April 2026

CVE-2026-29141: Seppmail secure email gateway improper input validation vulnerability

Seppmail · Secure Email Gateway

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags such as [signed OK].

7.7 CVSS 4.0 High EPSS 0.35% · top 74.3% CWE-20 · Improper input validation
7.7CVSS 4.0 base score
0.35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags such as [signed OK].

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-29141 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2026-29143Seppmail secure email gateway improper input validation vulnerabilitySEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an a…EPSS 0.43%7.8CVE-2026-29144Seppmail secure email gateway improper input validation vulnerabilitySEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge security tags using Unicode lookalike…EPSS 0.35%7.8CVE-2026-29139Seppmail secure email gateway authentication bypass via alternate path vulnerabilitySEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to reset a victim account password.EPSS 0.48%7.7CVE-2026-29140Seppmail secure email gateway improper certificate validation vulnerabilitySEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be used for future encryption to …EPSS 0.19%6.3CVE-2026-29138Seppmail secure email gateway ldap injection vulnerabilitySEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim another user's PGP signature as …EPSS 0.37%6.3CVE-2026-29142Seppmail secure email gateway vulnerabilitySEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted email.EPSS 0.19%6.3CVE-2026-29132Seppmail secure email gateway missing authentication for critical function vulnerabilitySEPPmail Secure Email Gateway before version 15.0.3 allows an attacker with access to a victim's GINA account to bypass a second-password check and r…EPSS 0.42%5.3CVE-2026-29137Seppmail secure email gateway improper input validation vulnerabilitySEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from users by crafting a long subject.EPSS 0.31%

Source: NIST National Vulnerability Database (record CVE-2026-29141), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.