CVE-2026-104082: SmarterTools SmarterMail
High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.
SmarterMail before build 9777 contains a remote code execution vulnerability that allows an attacker holding a SysAdmin-scoped access token to bypass the Volume Mount script-directory containment control by provisioning a new mail domain with an arbitrary FileStore root path inside the trusted Scripts directory via the domain-put endpoint. Attackers can disclose the Scripts path through the AddOrUpdateMount endpoint, clear the upload extension blacklist via the global-mail endpoint, then upload a malicious script through the ordinary mail file-storage upload API so that saving a CommandMount triggers RunScript before validation, resulting in a reverse shell executing as the SmarterMail service account with SYSTEM-level privileges.
Affected products
- SmarterTools SmarterMail
Published 2026-10-09. Last modified 2026-10-09.