Privilege Escalation in SmarterMail by SmarterTools
CVE-2026-104084

8.7HIGH

Key Information:

Vendor
CVE Published:
9 October 2026

What is CVE-2026-104084?

SmarterMail versions prior to build 9777 are vulnerable to a privilege escalation issue stemming from improper token validation during the refresh-token process. The flaw occurs when JSON Web Token (JWT) access and refresh tokens are issued with role claims that remain unverified against the user's current privileges. Attackers able to intercept a refresh token issued before an account's privilege is reduced can exploit the vulnerability to obtain new access tokens with elevated permissions. This malicious behavior can allow compromised accounts to maintain higher-level access rights, such as DomainAdmin or SysAdmin, even after a demotion occurs, posing a significant security threat until the token naturally expires.

Affected Version(s)

Smartermail 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

evan
.