CVE-2026-29143CRITICAL 9.1EPSS p16.1%

CVE-2026-29143CVE-2026-29143

Description

SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an attacker to control trusted headers.

Scoring

CVSS 3.19.1 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS0.25% probability of exploitation · percentile 16.1% · 2026-06-19T12:03:05Z
Published2026-04-02
Last modified2026-04-16

Underlying weaknesses· 1

CWE-20

References

  1. https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html#seppmail-vulnerability-disclosure-1503

1

TypeTargetConfidenceTier
WeaknessImproper Input Validationcwe-200%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-29133
CVE
CVE-2026-29139
CVE
CVE-2026-27441
CVE
CVE-2026-2743
CVE
CVE-2025-46610
CVE
CVE-2026-41113
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.