CVE-2026-8811: Path traversal in PDF generation module
SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An attacker can exploit this to create new files outside the intended directory, potentially placing files in web-accessible locations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SEPPmailto a version that resolves this vulnerability.Fixed in 15.0.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8811?
CVE-2026-8811 has a risk rating of 56, indicating a moderate severity level.
How do I fix CVE-2026-8811?
To fix CVE-2026-8811, upgrade to SEPPmail version 15.0.5 or later.
What systems are affected by CVE-2026-8811?
CVE-2026-8811 affects SEPPmail versions prior to 15.0.5.
What type of vulnerability is CVE-2026-8811?
CVE-2026-8811 is classified as a path traversal vulnerability.
What could an attacker do with CVE-2026-8811?
An attacker could exploit CVE-2026-8811 to create files outside the intended directory, potentially in web-accessible locations.