Skip to content
CVE-2026-104082: SmarterMail Remote Code Execution Vulnerability

CVE-2026-104082: SmarterMail Remote Code Execution Vulnerability

First seen 9 Oct 2026, 20:35 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 21:38 UTC
  • •CVE-2026-104082 affects SmarterMail versions before build 9777.
  • •Attackers can exploit the vulnerability to gain SYSTEM-level privileges.
  • •Organizations with internet-reachable mail servers are most at risk.

A remote code execution vulnerability, CVE-2026-104082, has been identified in SmarterMail versions prior to build 9777. The flaw allows attackers with SysAdmin access tokens to bypass security controls and execute malicious scripts, potentially gaining SYSTEM-level privileges. Organizations with internet-reachable mail servers are particularly at risk, especially if administrative interfaces or tokens are widely accessible. Successful exploitation could lead to significant disruption and unauthorized access to sensitive data. As of today, no active exploitation has been confirmed, but the vulnerability is rated as high severity with a CVSS score of 8.6. Immediate patching is recommended to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-09
CVE-2026-104082 published
SmarterMail vulnerability disclosed, allowing remote code execution via SysAdmin tokens.
Redpacketsecurity
2026-10-09
Vulnerability advisory released
VulnCheck published an advisory detailing the SmarterMail remote code execution flaw.
www.vulncheck.com

More articles in this cluster (2)

Following this threat?

Track CVE-2026-104082 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of SmarterMail are affected?
SmarterMail versions prior to build 9777 are affected by CVE-2026-104082.
Is there a patch available?
Yes, a fixed release is available, and organizations are urged to upgrade promptly.
What should I do if I cannot patch immediately?
Restrict administrative access and monitor for unusual token usage or configuration changes.