SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim another user's PGP signature as their own.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 02 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim another user's PGP signature as their own. | |
| Title | PGP Decryption Sender LDAP Injection | |
| First Time appeared |
Seppmail
Seppmail seppmail Secure Email Gateway |
|
| Weaknesses | CWE-90 | |
| CPEs | cpe:2.3:a:seppmail:seppmail_secure_email_gateway:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Seppmail
Seppmail seppmail Secure Email Gateway |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2026-04-02T08:47:49.544Z
Reserved: 2026-03-04T09:08:03.277Z
Link: CVE-2026-29138
No data.
Status : Received
Published: 2026-04-02T09:16:22.290
Modified: 2026-04-02T09:16:22.290
Link: CVE-2026-29138
No data.
OpenCVE Enrichment
No data.
Weaknesses