← Vulnerability feed

Vulnerability record · CVE-2026-7807 · published 8 May 2026

CVE-2026-7807: Smartertools smartermail path traversal vulnerability

Smartertools · Smartermail

SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint that allows authenticated users to read arbitrary .json files on the system. Attackers can exploit this vulnerability combined with weak encryption algorithms and hardcoded keys to decrypt and access stored passwords and 2FA secrets for all users.

8.7 CVSS 4.0 High EPSS 0.34% · top 74.8% CWE-22 · Path traversal
8.7CVSS 4.0 base score
0.34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint that allows authenticated users to read arbitrary .json files on the system. Attackers can exploit this vulnerability combined with weak encryption algorithms and hardcoded keys to decrypt and access stored passwords and 2FA secrets for all users.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-7807 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-52691SmarterMail unauthenticated arbitrary file upload leading to RCESmarterTools SmarterMail contains an unrestricted file upload flaw (CWE-434) that lets an unauthenticated attacker write files to any location on the…KEVEPSS 86%analysed9.3CVE-2026-24423SmarterMail ConnectToHub API unauthenticated remote code executionSmarterTools SmarterMail builds prior to 9511 expose the ConnectToHub API method without authentication, allowing an attacker to redirect the applica…KEVEPSS 88%analysed9.3CVE-2026-23760SmarterMail password reset API authentication bypassSmarterMail builds prior to 9511 expose a force-reset-password endpoint that accepts anonymous requests and does not verify the current password or a…KEVEPSS 97%analysed9.8CVE-2021-32234Smartertools smartermail vulnerabilitySmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows remote code execution.EPSS 2.2%9.8CVE-2019-7214SmarterMail deserialization of untrusted data enables unauthenticated RCESmarterTools SmarterMail 16.x before build 6985 deserializes untrusted data, letting an unauthenticated attacker execute commands on the server when …EPSS 85%analysed8.2CVE-2026-40514Smartertools smartermail vulnerabilitySmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints that use DES-CBC encryption wi…EPSS 0.26%8.2CVE-2019-7212Smartertools smartermail hard-coded credentials vulnerabilitySmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file atta…EPSS 1.0%8.1CVE-2020-29548Smartertools smartermail command injection vulnerabilityAn issue was discovered in SmarterTools SmarterMail through 100.0.7537. Meddler-in-the-middle attackers can pipeline commands after a POP3 STLS comma…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2026-7807), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.