HarborGuard / CVE
Back to search
HIGHCVE-2026-44129Published Modified CNA NCSC.ch

CVE-2026-44129: Server-side template injection

SEPPmail Secure Email Gateway before version 15.0.4 contains a server-side template injection vulnerability in the new GINA UI because an endpoint accepts attacker-controlled template, allowing remote attackers to execute arbitrary template expressions and potentially achieve remote code execution depending on the enabled template plugins.

Metrics

CVSS v4.0
8.3
Severity
HIGH
Fixed in
15.0.4
Affected Products
1

Fix available

15.0.4
Affected packages
  • SEPPmail AG / Secure Email Gateway
    < 15.0.4 (from 0)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N