news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-44125

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
9.3 Critical
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Risk score
74.4
Published
2026-05-08
Status
Published

SEPPmail Secure Email Gateway before version 15.0.4 fails to enforce authorization checks for multiple endpoints in the new GINA UI, allowing unauthenticated remote attackers to access functionality that should require a valid session.

Weaknesses

CWE-862

Coverage 1

Advisories and references