CVE-2026-9592: Sensitive Information Disclosure in HTTP header
SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SEPPmail Secure Email Gateway & SEPPmail Cloudto a version that resolves this vulnerability.Fixed in 15.0.4.2 - Compensating control
Mitigate session token disclosure risk in the GINA web portal by preventing the URL/session-token from being exposed via HTTP headers (e.g., strip/redact the relevant header and ensure session tokens are not carried in URL/headers) until upgraded to 15.0.4.2.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9592?
CVE-2026-9592 has a high severity rating of 7.5 based on CVSS.
What type of vulnerability is CVE-2026-9592?
CVE-2026-9592 is a sensitive information disclosure vulnerability that can allow an attacker to hijack a user session.
How do I fix CVE-2026-9592?
To fix CVE-2026-9592, upgrade your SEPPmail Secure Email Gateway or SEPPmail Cloud software to version 15.0.4.2 or later.
What software is affected by CVE-2026-9592?
CVE-2026-9592 affects SEPPmail Secure Email Gateway and SEPPmail Cloud versions prior to 15.0.4.2.
What are the potential impacts of CVE-2026-9592?
CVE-2026-9592 can allow attackers to replay and hijack user sessions, compromising sensitive information.