GHSA-4rp5-r82m-g6p3HighCVSS 7.2

SmarterMail before build 9777 contains a remote code execution vulnerability that allows an...

Published
October 9, 2026
Last Modified
October 9, 2026

🔗 CVE IDs covered (1)

📋 Description

SmarterMail before build 9777 contains a remote code execution vulnerability that allows an attacker holding a SysAdmin-scoped access token to bypass the Volume Mount script-directory containment control by provisioning a new mail domain with an arbitrary FileStore root path inside the trusted Scripts directory via the domain-put endpoint. Attackers can disclose the Scripts path through the AddOrUpdateMount endpoint, clear the upload extension blacklist via the global-mail endpoint, then upload a malicious script through the ordinary mail file-storage upload API so that saving a CommandMount triggers RunScript before validation, resulting in a reverse shell executing as the SmarterMail service account with SYSTEM-level privileges.

🔗 References (4)