Smartermail CVE Vulnerabilities
By Smartertools — 2 known vulnerabilities
Critical
1
High
1
Medium
0
Low
0
None
0
All Smartermail CVEs
CVE-2026-7807
8.1
high
SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint that allows authenticated users to read arbitrary .json files on the system. Attackers can exploit this vulnerability combined with weak encryption algorithms
May 8, 2026
CVE-2025-52691
10.0
critical
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
Dec 29, 2025