Unrated severityNVD Advisory· Published Jul 17, 2026· Updated Jul 17, 2026
Sensitive Information Disclosure in HTTP header
CVE-2026-9592
Description
SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header.
Affected products
2- Range: <15.0.4.2
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.