vulnerability
Published 2026-10-09
Verified 2026-10-10

SmarterMail before Build 9777: VulnCheck publishes three CVEs fixed on 8 Oct — stale JWT role claims let demoted admins keep SysAdmin rights (CVSS 8.8), a SysAdmin-token chain to a reverse shell (7.2), and a stored XSS that fires when a crafted calendar invite is opened

VulnCheck published three CVEs on 9 October 2026 for SmarterTools SmarterMail, all fixed in Build 9777 released on 8 October. CVE-2026-104084 (CVSS 3.1 8.8, CVSS 4.0 8.7): access and refresh JWTs carry the role at issue time and POST /api/v1/auth/refresh-token does not recheck it, so a captured refresh token from before an admin demotion, or a demoted user whose session was idle, can mint new tokens that keep DomainAdmin or SysAdmin rights until expiry. CVE-2026-104082 (7.2; 4.0 8.6): an attacker holding a SysAdmin-scoped token can create a mail domain whose FileStore root sits inside the trusted Scripts folder, learn the path through AddOrUpdateMount, clear the upload extension blacklist, upload a script through normal file storage and have a CommandMount run it, giving a reverse shell as the SmarterMail service. CVE-2026-104083 (6.1): a mutation XSS using a style element inside MathML gets past the HTML sanitiser, so a crafted iCal invite runs script in the recipient's webmail session when opened. No exploitation of these three has been reported, but earlier SmarterMail flaws (CVE-2025-52691, CVE-2026-23760 and CVE-2026-24423) were exploited in the wild in early 2026, so patch quickly. Primary: VulnCheck advisories; vendor: SmarterMail release notes.

Product
SmarterTools SmarterMail (Windows/Linux mail server and webmail)
Versions
All builds before Build 9777
CVSS
(CVSS 3.1, CVE-2026-104084); 7.2 (CVE-2026-104082); 6.1 (CVE-2026-104083)
Exploited in Australia?
unknown
Patch to
Upgrade SmarterMail to Build 9777 (8 Oct 2026) or later. After demoting any admin, revoke that user's sessions and refresh tokens; review SysAdmin accounts and API tokens, mail-domain FileStore paths and the upload extension blacklist for unexpected changes.

Primary: VulnCheck — SmarterMail Build 9777 stale JWT role claim privilege escalation (CVE-2026-104084, 9 Oct 2026) · Vendor: SmarterTools — SmarterMail release notes (Build 9777, 8 Oct 2026) · CVE: CVE-2026-104084, CVE-2026-104082, CVE-2026-104083, CVE-2025-52691, CVE-2026-23760, CVE-2026-24423 · VulnCheck — SmarterMail Build 9777 SysAdmin remote code execution via Volume Mount (CVE-2026-104082)

vulnerabilities identity