PatchSiren cyber security CVE debrief
CVE-2026-7864 SEPPmail AG CVE debrief
CVE-2026-7864 is a medium-severity information disclosure issue in SEPPmail Secure Email Gateway before version 15.0.4. An unauthenticated endpoint in the new GINA UI can expose server environment variables, which may reveal sensitive system details to remote attackers. The supplied metadata maps this to CWE-497 and shows no Known Exploited Vulnerabilities (KEV) listing in the provided corpus.
- Vendor
- SEPPmail AG
- Product
- Secure Email Gateway
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-08
- Original CVE updated
- 2026-05-18
- Advisory published
- 2026-05-08
- Advisory updated
- 2026-05-18
Who should care
Administrators and security teams running SEPPmail Secure Email Gateway deployments before 15.0.4, especially where the new GINA UI is reachable from untrusted networks.
Technical summary
The issue is described as an unauthenticated endpoint in the new GINA UI that exposes server environment variables. Because the request path requires no authentication and is reachable remotely, an attacker can obtain sensitive system information without prior access. The provided NVD metadata associates the weakness with CWE-497 and a network-reachable, no-auth attack profile.
Defensive priority
High for exposed SEPPmail instances below 15.0.4, because the flaw is remotely reachable and requires no authentication, even though the observed impact is information disclosure rather than code execution.
Recommended defensive actions
- Upgrade SEPPmail Secure Email Gateway to version 15.0.4 or later.
- Restrict exposure of the GINA UI to trusted management networks until patched.
- Review any logs or monitoring for requests to the affected endpoint before remediation.
- Treat exposed environment variables as potentially sensitive and rotate any secrets that may have been disclosed if exposure is confirmed.
- Validate that any compensating access controls do not leave the unauthenticated endpoint reachable from untrusted networks.
Evidence notes
The CVE description states that SEPPmail Secure Email Gateway before 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI. The provided NVD metadata lists CWE-497 as the weakness and shows a CVSS v4 network/no-auth vector with medium severity. The corpus also includes a vendor release notes reference and an InfoGuard post referenced by NCSC. NVD vulnStatus is marked Deferred in the supplied source item.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-7864 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-7864
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-7864 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-7864
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html
-
Source reference
Unverified legacy reference
URL: https://labs.infoguard.ch/posts/seppmail_secure_e-mail_gateway_rce_vulnerabilities_cve-2026-2743_cve-2026-7864_cve-2026-44127_cve-2026-44128/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.