Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104084— SmarterMail < Build 9777 Stale JWT Role Claim Privilege Escalation via Refresh Token

Quick assessment

Affected
Smartertools Smartermail
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 SmarterMail 9777 版本之前,存在一个权限提升漏洞。该漏洞源于在颁发 JWT(JSON Web Token)访问令牌和刷新令牌时,令牌中嵌入了角色声明(role claim),但在通过 POST /api/v1/auth/refresh-token 接口使用刷新令牌换取新访问令牌时,系统未重新验证该角色声明是否与账户当前的实际角色一致。攻击者若捕获了在管理员降级之前颁发的刷新令牌,或捕获了在降级发生时其会话未处于活跃轮询状态的已降级用户的刷新令牌,即可重放该过期的刷新令牌,从而获取新的访问令牌,且

CVSS 8.8 · High

Affected Version Matrix 1

VendorProduct Version RangeStatus
Smartertools Smartermail < Build 9777 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104084

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SmarterMail < Build 9777 Stale JWT Role Claim Privilege Escalation via Refresh Token
Source: CVE Program / CVE List V5
Vulnerability Description
SmarterMail before build 9777 contains a privilege escalation vulnerability where JWT access and refresh tokens embed a role claim at issuance that is not revalidated against the account's current role when redeemed through POST /api/v1/auth/refresh-token. Attackers who capture a refresh token issued before an administrator demotion, or a demoted user whose session was not actively polling at the time of demotion, can replay the stale token to obtain a new access token retaining the higher-privilege role (such as DomainAdmin or SysAdmin) until natural token expiry.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的会话过期机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Smartertools Smartermail 0 ~ Build 9777 -

II. Public POCs for CVE-2026-104084

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104084

请登录查看更多情报信息。

Other References for CVE-2026-104084 (1)

Same Patch Batch · Smartertools · 2026-10-09 · 3 CVEs total

CVE-2026-104082 7.2 HIGH SmarterMail < Build 9777 SysAdmin Remote Code Execution via Volume Mount
CVE-2026-104083 6.1 MEDIUM SmarterMail < Build 9777 Stored Mutation XSS via MathML Foreign Content

IV. Related Vulnerabilities

V. Comments for CVE-2026-104084

No comments yet


Leave a comment