High severity8.8NVD Advisory· Published Oct 9, 2026
CVE-2026-104084
CVE-2026-104084
Description
SmarterMail before build 9777 contains a privilege escalation vulnerability where JWT access and refresh tokens embed a role claim at issuance that is not revalidated against the account's current role when redeemed through POST /api/v1/auth/refresh-token. Attackers who capture a refresh token issued before an administrator demotion, or a demoted user whose session was not actively polling at the time of demotion, can replay the stale token to obtain a new access token retaining the higher-privilege role (such as DomainAdmin or SysAdmin) until natural token expiry.
Affected products
1- Range: <9777
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.