在 SmarterMail 9777 版本之前,存在一个权限提升漏洞。该漏洞源于在颁发 JWT(JSON Web Token)访问令牌和刷新令牌时,令牌中嵌入了角色声明(role claim),但在通过 POST /api/v1/auth/refresh-token 接口使用刷新令牌换取新访问令牌时,系统未重新验证该角色声明是否与账户当前的实际角色一致。攻击者若捕获了在管理员降级之前颁发的刷新令牌,或捕获了在降级发生时其会话未处于活跃轮询状态的已降级用户的刷新令牌,即可重放该过期的刷新令牌,从而获取新的访问令牌,且
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Smartertools | Smartermail | < Build 9777 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Smartertools | Smartermail | 0 ~ Build 9777 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104082 | 7.2 HIGH | SmarterMail < Build 9777 SysAdmin Remote Code Execution via Volume Mount |
| CVE-2026-104083 | 6.1 MEDIUM | SmarterMail < Build 9777 Stored Mutation XSS via MathML Foreign Content |
No comments yet