HarborGuard / CVE
Back to search
HIGHCVE-2026-44127Published Modified CNA NCSC.ch

CVE-2026-44127: Local File Inclusion (LFI) and Arbitrary File Deletion

SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal vulnerability in the identifier parameter of /api.app/attachment/preview that allows remote attackers to read arbitrary local files and trigger deletion of files in the targeted directory with the privileges of the api.app process.

Metrics

CVSS v4.0
8.8
Severity
HIGH
Fixed in
15.0.4
Affected Products
1

Fix available

15.0.4
Affected packages
  • SEPPmail AG / Secure Email Gateway
    < 15.0.4 (from 0)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N