← All CVEs

CVE-2026-7864

medium · 6.9

SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain sensitive system information.

6.9
CVSS
17.0%
EPSS (exploit prob.)
97th
EPSS percentile
2026-05-08
Published

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Weaknesses

CWE-497

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-7864