๐Ÿ” CVE Alert

CVE-2026-104082

HIGH 7.2

SmarterMail < Build 9777 SysAdmin Remote Code Execution via Volume Mount

CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th

SmarterMail before build 9777 contains a remote code execution vulnerability that allows an attacker holding a SysAdmin-scoped access token to bypass the Volume Mount script-directory containment control by provisioning a new mail domain with an arbitrary FileStore root path inside the trusted Scripts directory via the domain-put endpoint. Attackers can disclose the Scripts path through the AddOrUpdateMount endpoint, clear the upload extension blacklist via the global-mail endpoint, then upload a malicious script through the ordinary mail file-storage upload API so that saving a CommandMount triggers RunScript before validation, resulting in a reverse shell executing as the SmarterMail service account with SYSTEM-level privileges.

CWE CWE-94
Vendor smartertools
Product smartermail
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for smartertools smartermail

Be the first to know when new high vulnerabilities affecting smartertools smartermail are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Smartertools / Smartermail
0 < Build 9777

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
smartertools.com: https://www.smartertools.com/smartermail/release-notes/current#/9526:~:text=Build%209777%20(Oct%208%2C%202026) vulncheck.com: https://www.vulncheck.com/advisories/smartermail-build-9777-sysadmin-remote-code-execution-via-volume-mount

Credits

evan