Remote Code Execution Vulnerability in SmarterMail by SmarterTools
CVE-2026-104082

8.6HIGH

Key Information:

Vendor
CVE Published:
9 October 2026

What is CVE-2026-104082?

SmarterMail prior to build 9777 is susceptible to a remote code execution vulnerability. This flaw arises from improper controls surrounding the Volume Mount script-directory. An authenticated attacker with SysAdmin-level access can exploit this vulnerability by creating a new mail domain and specifying a malicious FileStore root path. Through the domain-put endpoint, they can manipulate the trusted Scripts directory. By leveraging the AddOrUpdateMount endpoint, an attacker can disclose the Scripts path and circumvent the upload extension blacklist using the global-mail endpoint. This chain of actions enables the attacker to upload a harmful script via the standard mail file storage upload API. The exploitation culminates in the execution of the script when saving a CommandMount, which triggers the RunScript function without adequate validation, leading to a reverse shell being executed with SYSTEM-level privileges.

Affected Version(s)

Smartermail 0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

evan
.