Remote Code Execution Vulnerability in SmarterMail by SmarterTools
CVE-2026-104082
What is CVE-2026-104082?
SmarterMail prior to build 9777 is susceptible to a remote code execution vulnerability. This flaw arises from improper controls surrounding the Volume Mount script-directory. An authenticated attacker with SysAdmin-level access can exploit this vulnerability by creating a new mail domain and specifying a malicious FileStore root path. Through the domain-put endpoint, they can manipulate the trusted Scripts directory. By leveraging the AddOrUpdateMount endpoint, an attacker can disclose the Scripts path and circumvent the upload extension blacklist using the global-mail endpoint. This chain of actions enables the attacker to upload a harmful script via the standard mail file storage upload API. The exploitation culminates in the execution of the script when saving a CommandMount, which triggers the RunScript function without adequate validation, leading to a reverse shell being executed with SYSTEM-level privileges.
Affected Version(s)
Smartermail 0
