Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104082— SmarterMail < Build 9777 SysAdmin Remote Code Execution via Volume Mount

Quick assessment

Affected
Smartertools Smartermail
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 SmarterMail build 9777 之前的版本中,存在一个远程代码执行漏洞。该漏洞允许持有 SysAdmin 作用域访问令牌的攻击者,通过 domain-put 端点,使用受信任的 Scripts 目录内的任意 FileStore 根路径配置新的邮件域,从而绕过 Volume Mount 脚本目录的隔离控制。攻击者可以通过 AddOrUpdateMount 端点泄露 Scripts 目录的路径,通过 global-mail 端点清除上传扩展名的黑名单,然后通过常规的邮件文件存储上传 API 上传恶意脚

CVSS 7.2 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104082

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SmarterMail < Build 9777 SysAdmin Remote Code Execution via Volume Mount
Source: CVE Program / CVE List V5
Vulnerability Description
SmarterMail before build 9777 contains a remote code execution vulnerability that allows an attacker holding a SysAdmin-scoped access token to bypass the Volume Mount script-directory containment control by provisioning a new mail domain with an arbitrary FileStore root path inside the trusted Scripts directory via the domain-put endpoint. Attackers can disclose the Scripts path through the AddOrUpdateMount endpoint, clear the upload extension blacklist via the global-mail endpoint, then upload a malicious script through the ordinary mail file-storage upload API so that saving a CommandMount triggers RunScript before validation, resulting in a reverse shell executing as the SmarterMail service account with SYSTEM-level privileges.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Smartertools Smartermail 0 ~ Build 9777 -

II. Public POCs for CVE-2026-104082

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104082

请登录查看更多情报信息。

Other References for CVE-2026-104082 (2)

Same Patch Batch · Smartertools · 2026-10-09 · 3 CVEs total

CVE-2026-104084 8.8 HIGH SmarterMail < Build 9777 Stale JWT Role Claim Privilege Escalation via Refresh Token
CVE-2026-104083 6.1 MEDIUM SmarterMail < Build 9777 Stored Mutation XSS via MathML Foreign Content

IV. Related Vulnerabilities

V. Comments for CVE-2026-104082

No comments yet


Leave a comment