CVE-2026-44129
Deferred Deferred - Pending Action
Server-Side Template Injection in SEPPmail Secure Email Gateway

Publication date: 2026-05-08

Last updated on: 2026-05-18

Assigner: Switzerland Government Common Vulnerability Program

Description
SEPPmail Secure Email Gateway before version 15.0.4 contains a server-side template injection vulnerability in the new GINA UI because an endpoint accepts attacker-controlled template, allowing remote attackers to execute arbitrary template expressions and potentially achieve remote code execution depending on the enabled template plugins.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-08
Last Modified
2026-05-18
Generated
2026-06-19
AI Q&A
2026-05-08
EPSS Evaluated
2026-06-18
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
seppmail secure_email_gateway to 15.0.4 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1336 The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in SEPPmail Secure Email Gateway versions before 15.0.4. It is a server-side template injection issue in the new GINA UI. An attacker can send a specially crafted template to an endpoint that accepts it without proper validation, allowing the attacker to execute arbitrary template expressions on the server.

Depending on the enabled template plugins, this can lead to remote code execution, meaning the attacker could run malicious code on the affected server.

Impact Analysis

The vulnerability can allow remote attackers to execute arbitrary code on the server running SEPPmail Secure Email Gateway. This can lead to unauthorized access, data compromise, disruption of email services, and potentially full control over the affected system.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-44129. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart