← Back to CVE List
Vulnerability Intelligence Report
SmarterTools SmarterMail < Build 9560 Server Local File Inclusion via the /api/v1/report/summary/{type} API

CVE-2026-7807

SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint that allows authenticated users to read arbitrary .json files on the system. Attackers can exploit this vulnerability combined with weak encryption algorithms and hardcoded keys to decrypt and access stored passwords and 2FA secrets for all users.

Path Traversal No Active Exploit Signals
CVSS Base Score
8.7
HIGH
EPSS Probability:0.30%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-22 ↗CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Affected Products & Versions

Vendor Product Affected Versions
SmarterTools Inc. SmarterMail 0 < 9560 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.296%
Vulnerability Class
Path Traversal

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulnCheck · Bug Bounty Provider · USA
Reserved2026-05-04T20:56:15
Published2026-05-08T19:54:33
Patch Date2026-05-08
Last Updated2026-07-14T22:03:56

LINK COPIED TO CLIPBOARD