Executive brief
SmarterMail is an enterprise-grade email and collaboration server. A security flaw in how the system generates encryption keys for shared files and emails allows unauthorized individuals to bypass security controls. By exploiting this weakness, an attacker could gain access to private emails, attachments, and stored files without needing a password or prior access to the system.
Technical details
SmarterTools SmarterMail builds prior to 9610 utilize DES-CBC encryption for file and email sharing tokens. The keys and initialization vectors (IVs) for this encryption are derived from the System.Random class, which is seeded with insufficient entropy. This reduces the possible seed space to approximately 19,000 values. An unauthenticated remote attacker can use the attachment download endpoint as a decryption oracle to identify the active seed. Once the seed is determined, the attacker can derive the corresponding encryption keys and IVs to forge valid sharing tokens, granting unauthorized access to arbitrary emails, attachments, and file storage contents. The issue is resolved in SmarterMail build 9610.
Affected products
- SmarterTools SmarterMail Prior to build 9610
Timeline
- 2026-04-24: patched: Build 9610 released to address the issue.
- 2026-04-27: disclosed: Initial vulnerability disclosure.
- 2026-04-27: advisory: NVD and VulnCheck advisories published.