CVE-2026-27441: PDF Password CMDi
Published Mar 4, 2026
·Updated
SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS command execution.
Affected Software
2 affected components
SEPPmail Secure Email Gateway<15.0.1
SEPPmail SEPPmail<15.0.1
Event History
Mar 4, 2026
CVE Published
via MITRE·08:49 AM
Data Sourced
via MITRE·08:49 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-27441?
CVE-2026-27441 is classified as a critical vulnerability due to its potential for unauthorized OS command execution.
2
How do I fix CVE-2026-27441?
To remediate CVE-2026-27441, upgrade to SEPPmail Secure Email Gateway version 15.0.1 or later.
3
What kind of attacks can CVE-2026-27441 lead to?
CVE-2026-27441 can lead to OS command injection attacks, allowing attackers to execute arbitrary commands on the affected system.
4
Which versions of SEPPmail Secure Email Gateway are affected by CVE-2026-27441?
CVE-2026-27441 affects SEPPmail Secure Email Gateway versions prior to 15.0.1.
5
How does CVE-2026-27441 impact system security?
CVE-2026-27441 undermines system security by allowing attackers to bypass encryption mechanisms and execute malicious commands.