CVE-2026-25067: SmarterTools SmarterMail < Build 9518 Unauthenticated background-of-the-day Path Coercion
SmarterTools SmarterMail versions prior to build 9518 contain an unauthenticated path coercion vulnerability in the background-of-the-day preview endpoint. The application base64-decodes attacker-supplied input and uses it as a filesystem path without validation. On Windows systems, this allows UNC paths to be resolved, causing the SmarterMail service to initiate outbound SMB authentication attempts to attacker-controlled hosts. This can be abused for credential coercion, NTLM relay attacks, and unauthorized network authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25067?
The severity of CVE-2026-25067 is considered high due to its unauthenticated nature, allowing attackers to exploit the vulnerability without user authentication.
How do I fix CVE-2026-25067?
To fix CVE-2026-25067, upgrade to SmarterTools SmarterMail build 9518 or later, which addresses this vulnerability.
What version of SmarterMail is affected by CVE-2026-25067?
SmarterMail versions prior to build 9518 are affected by CVE-2026-25067.
What type of vulnerability is CVE-2026-25067?
CVE-2026-25067 is classified as an unauthenticated path coercion vulnerability.
Can CVE-2026-25067 be exploited remotely?
Yes, CVE-2026-25067 can be exploited remotely since it does not require authentication for the attack.