OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-104084 (CVSS 8.7)

NVD · officialPublished Oct 9, 2026Risk 37/100

SmarterMail before build 9777 contains a privilege escalation vulnerability where JWT access and refresh tokens embed a role claim at issuance that is not revalidated against the account's current role when redeemed through POST /api/v1/auth/refresh-token. Attackers who capture a refresh token issued before an administrator demotion, or a demoted user whose session was not actively polling at the time of demotion, can replay the stale token to obtain a new access token retaining the higher-privilege role (such as DomainAdmin or SysAdmin) until natural token expiry.

CVSS
8.7
AV:NetworkAC:LowPR:LowUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source