Subject Sanitization Bypass in SEPPmail Secure Email Gateway
CVE-2026-29144
7.8HIGH
What is CVE-2026-29144?
The SEPPmail Secure Email Gateway prior to version 15.0.3 is susceptible to an exploit where an attacker can bypass the subject sanitization process. This vulnerability enables the crafting of security tags through the use of Unicode lookalike characters, potentially misleading users and undermining the integrity of email communications. Proper patching and updates to version 15.0.3 or later are essential to safeguard against such attacks.
Affected Version(s)
Secure Email Gateway 0 < 15.0.3
References
CVSS V4
Score:
7.8
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Andris Suter-Dörig
Matteo Scarlata
Kenny Paterson
