Path Traversal Vulnerability in SeppMail User Web Interface
CVE-2026-2743

10CRITICAL

Key Information:

Vendor

Seppmail

Status
Vendor
CVE Published:
5 March 2026

What is CVE-2026-2743?

A vulnerability in the SeppMail User Web Interface allows for arbitrary file write due to a path traversal issue during the upload process. This weakness is particularly relevant to the large file transfer feature, which can be exploited to achieve remote code execution. This issue affects SeppMail versions 15.0.2.1 and earlier, presenting a significant security risk if not addressed promptly.

Affected Version(s)

SeppMail Linux unknown <= 15.0.2.1

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Manuel Feifel and Dario Weiss of InfoGuard Labs
.