CVE-2025-52691

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

critical 10.0 CVSS 3.1
Published: Dec 29, 2025
Modified: Jan 27, 2026
Vendor: Smartertools
Product: Smartermail

Description

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

References