Path Traversal Vulnerability in SeppMail User Web Interface
CVE-2026-2743

10CRITICAL

Key Information:

Vendor

Seppmail

Status
Vendor
CVE Published:
5 March 2026

Badges

๐Ÿ‘พ Exploit Exists๐Ÿ“ฐ News Worthy

What is CVE-2026-2743?

A vulnerability in the SeppMail User Web Interface allows for arbitrary file write due to a path traversal issue during the upload process. This weakness is particularly relevant to the large file transfer feature, which can be exploited to achieve remote code execution. This issue affects SeppMail versions 15.0.2.1 and earlier, presenting a significant security risk if not addressed promptly.

Affected Version(s)

SeppMail Linux unknown <= 15.0.2.1

News Articles

SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access

Seven SEPPMail Secure E-Mail Gateway flaws disclosed, including RCE, path traversal, authorization, deserialization, and eval injection flaws.

1 month ago

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • ๐Ÿ“ฐ

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

Credit

Manuel Feifel and Dario Weiss of InfoGuard Labs
.