CVE-2026-7864: Exposure of Sensitive Information to an Unauthorized Actor
SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain sensitive system information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SEPPmail Secure Email Gatewayto a version that resolves this vulnerability.Fixed in 15.0.4 - Compensating control
Restrict network access to the new GINA UI/unauthenticated endpoint so remote attackers cannot reach it until SEPPmail Secure Email Gateway is upgraded to 15.0.4 or later.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7864?
CVE-2026-7864 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2026-7864?
To resolve CVE-2026-7864, upgrade your SEPPmail Secure Email Gateway to version 15.0.4 or later.
What information can be exposed due to CVE-2026-7864?
CVE-2026-7864 allows unauthorized actors to access sensitive server environment variables.
Which versions of SEPPmail Secure Email Gateway are affected by CVE-2026-7864?
CVE-2026-7864 affects SEPPmail Secure Email Gateway versions prior to 15.0.4.
Is authentication required to exploit CVE-2026-7864?
No, CVE-2026-7864 can be exploited through an unauthenticated endpoint.