PatchSiren cyber security CVE debrief
CVE-2026-7864 SEPPmail AG CVE debrief
CVE-2026-7864 is a medium-severity information disclosure issue in SEPPmail Secure Email Gateway before version 15.0.4. An unauthenticated endpoint in the new GINA UI can expose server environment variables, which may reveal sensitive system details to remote attackers. The supplied metadata maps this to CWE-497 and shows no Known Exploited Vulnerabilities (KEV) listing in the provided corpus.
- Vendor
- SEPPmail AG
- Product
- Secure Email Gateway
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-08
- Original CVE updated
- 2026-05-18
- Advisory published
- 2026-05-08
- Advisory updated
- 2026-05-18
Who should care
Administrators and security teams running SEPPmail Secure Email Gateway deployments before 15.0.4, especially where the new GINA UI is reachable from untrusted networks.
Technical summary
The issue is described as an unauthenticated endpoint in the new GINA UI that exposes server environment variables. Because the request path requires no authentication and is reachable remotely, an attacker can obtain sensitive system information without prior access. The provided NVD metadata associates the weakness with CWE-497 and a network-reachable, no-auth attack profile.
Defensive priority
High for exposed SEPPmail instances below 15.0.4, because the flaw is remotely reachable and requires no authentication, even though the observed impact is information disclosure rather than code execution.
Recommended defensive actions
- Upgrade SEPPmail Secure Email Gateway to version 15.0.4 or later.
- Restrict exposure of the GINA UI to trusted management networks until patched.
- Review any logs or monitoring for requests to the affected endpoint before remediation.
- Treat exposed environment variables as potentially sensitive and rotate any secrets that may have been disclosed if exposure is confirmed.
- Validate that any compensating access controls do not leave the unauthenticated endpoint reachable from untrusted networks.
Evidence notes
The CVE description states that SEPPmail Secure Email Gateway before 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI. The provided NVD metadata lists CWE-497 as the weakness and shows a CVSS v4 network/no-auth vector with medium severity. The corpus also includes a vendor release notes reference and an InfoGuard post referenced by NCSC. NVD vulnStatus is marked Deferred in the supplied source item.
Official resources
Published 2026-05-08 and last modified 2026-05-18 in the supplied CVE record. No KEV entry is present in the provided data, and the NVD item in the corpus is marked Deferred.