- What: Multiple vulnerabilities in SmarterTools SmarterMail
- Impact: Remote authenticated attackers can bypass path restrictions and access files outside mailbox paths
[WID-SEC-2026-3212] SmarterTools SmarterMail: Mehrere Schwachstellen CVSS Base Score 8.8 (hoch) CVSS Temporal Score 7.7 (hoch) Remoteangriff ja Datum 06.09.2026 Stand 07.09.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Sonstiges UNIX Windows Produktbeschreibung SmarterMail von SmarterTools ist eine Mailserver-Software. Produkte 06.09.2026 SmarterTools SmarterMail <Build 9742 Angriff Angriff Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in SmarterTools SmarterMail ausnutzen, um Pfadbeschränkungen zu umgehen und auf Dateien außerhalb vorgesehener Mailbox-Pfade zuzugreifen sowie möglicherweise administrative API-Funktionen, Systemadministrator-Tokens, Berechtigungen oder zwischengespeicherte Authentifizierungsinformationen unberechtigt zu verwenden. CVE Informationen Versionshistorie Feedback zum Advisory geben