Subject Sanitization Bypass in SEPPmail Secure Email Gateway
CVE-2026-29144

7.8HIGH

Key Information:

Vendor

Seppmail

Vendor
CVE Published:
2 April 2026

What is CVE-2026-29144?

The SEPPmail Secure Email Gateway prior to version 15.0.3 is susceptible to an exploit where an attacker can bypass the subject sanitization process. This vulnerability enables the crafting of security tags through the use of Unicode lookalike characters, potentially misleading users and undermining the integrity of email communications. Proper patching and updates to version 15.0.3 or later are essential to safeguard against such attacks.

Affected Version(s)

Secure Email Gateway 0 < 15.0.3

References

CVSS V4

Score:
7.8
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andris Suter-Dörig
Matteo Scarlata
Kenny Paterson
.