Junglewise Threat Intelligence

CVE-2026-7807: SmarterTools SmarterMail local file inclusion in reporting API

CVE-2026-7807 · Severity: high · CVSS 8.1 · Published 2026-05-08

Technologies: SmarterTools SmarterMail. Vendors: SmarterTools.

Executive brief

SmarterMail is an enterprise-grade email and collaboration server. A security vulnerability in its reporting interface allows authenticated users to access sensitive system files. By exploiting this flaw alongside weak internal encryption, an attacker could steal passwords and two-factor authentication (2FA) secrets for every user on the system, leading to a total compromise of the email environment.

Technical details

A local file inclusion (LFI) vulnerability exists in the `/api/v1/report/summary/{type}` API endpoint of SmarterTools SmarterMail. The root cause is improper path validation (CWE-22) in the `{type}` parameter, which allows an authenticated attacker to traverse the file system and read arbitrary .json files. When combined with the application's use of weak encryption algorithms and hardcoded cryptographic keys, an attacker can decrypt sensitive configuration files to retrieve stored passwords and 2FA secrets for all users. The vulnerability is addressed in SmarterMail build 9560 and later.

Affected products

  • SmarterTools SmarterMail Builds prior to 9560

Timeline

  • 2026-05-08: disclosed
  • 2026-05-08: advisory

References

Related threats