CVE-2026-29143: S/MIME Decryption Impersonation
Published Apr 2, 2026
·Updated
SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an attacker to control trusted headers.
Affected Software
2 affected components
SEPPmail SEPPmail Secure Email Gateway<15.0.3
SEPPmail Secure Email Gateway<15.0.3
Event History
Apr 2, 2026
CVE Published
via MITRE·08:49 AM
Data Sourced
via MITRE·08:49 AM
DescriptionWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-29143?
CVE-2026-29143 is considered a high severity vulnerability due to its potential for impersonation attacks.
2
How do I fix CVE-2026-29143?
To mitigate CVE-2026-29143, upgrade your SEPPmail Secure Email Gateway to version 15.0.3 or later.
3
What type of attack is possible with CVE-2026-29143?
CVE-2026-29143 allows an attacker to perform S/MIME decryption impersonation, gaining control over trusted headers.
4
Is my SEPPmail Secure Email Gateway affected by CVE-2026-29143?
If you are using SEPPmail Secure Email Gateway versions prior to 15.0.3, your system is vulnerable to CVE-2026-29143.
5
What components are impacted by CVE-2026-29143?
CVE-2026-29143 impacts the S/MIME encryption functionality within the SEPPmail Secure Email Gateway.