CVE-2026-104084
Received Received - Intake

Privilege Escalation via Stale JWT Tokens in SmarterMail

Vulnerability report for CVE-2026-104084, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: VulnCheck

Description

SmarterMail before build 9777 contains a privilege escalation vulnerability where JWT access and refresh tokens embed a role claim at issuance that is not revalidated against the account's current role when redeemed through POST /api/v1/auth/refresh-token. Attackers who capture a refresh token issued before an administrator demotion, or a demoted user whose session was not actively polling at the time of demotion, can replay the stale token to obtain a new access token retaining the higher-privilege role (such as DomainAdmin or SysAdmin) until natural token expiry.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Smartertools Smartermail 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a privilege escalation flaw in SmarterMail versions before build 9777. It involves JWT tokens that embed a user's role claim when issued. When a user's role is downgraded, the system does not revalidate this role claim during token refresh. Attackers can exploit this by replaying a stale refresh token to obtain a new access token with elevated privileges, such as DomainAdmin or SysAdmin, until the token expires.

Detection Guidance

Monitor for unusual token refresh activity, especially requests to POST /api/v1/auth/refresh-token with elevated role claims that do not match current user roles. Check logs for repeated refresh token usage from the same user account.

Impact Analysis

If you are an administrator or user with elevated privileges in SmarterMail, this vulnerability could allow attackers to gain unauthorized access to your account with your previous higher privileges. This could lead to data breaches, unauthorized modifications, or other malicious activities within the system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Unauthorized privilege escalation could result in data breaches, improper access to personal health information, or other regulatory violations, potentially leading to legal penalties and reputational damage.

Mitigation Strategies

Update SmarterMail to build 9777 or later immediately. Revoke all existing refresh tokens and force users to re-authenticate. Review user roles and demote any unauthorized elevated accounts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104084. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart