← back
CVE-2026-7864mediumCWE-497

Exposure of Sensitive Information to an Unauthorized Actor

18Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.9epss 17%
exploitation probability
17%top 3% of all CVEs
observed exploitation
nono source reports it
SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain sensitive system information.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N