CVE-2026-29141: Bounded Subject Tag Sanitization
Published Apr 2, 2026
·Updated
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags such as [signed OK].
Affected Software
2 affected components
SEPPmail SEPPmail Secure Email Gateway<15.0.3
SEPPmail Secure Email Gateway<15.0.3
Event History
Apr 2, 2026
CVE Published
via MITRE·08:34 AM
Data Sourced
via MITRE·08:34 AM
DescriptionWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-29141?
CVE-2026-29141 has a high severity rating of 7.7 according to the CVSS score.
2
What does CVE-2026-29141 allow an attacker to do?
CVE-2026-29141 allows an attacker to bypass subject sanitization and forge tags such as [signed OK] in SEPPmail Secure Email Gateway.
3
How can CVE-2026-29141 be mitigated?
To mitigate CVE-2026-29141, it is recommended to upgrade the SEPPmail Secure Email Gateway to version 15.0.3 or later.
4
What versions of SEPPmail are affected by CVE-2026-29141?
CVE-2026-29141 affects SEPPmail Secure Email Gateway versions prior to 15.0.3.
5
When was CVE-2026-29141 published?
CVE-2026-29141 was published on April 2, 2026.