CVE-2026-104084 | SmarterTools SmarterMail up to 9560 refresh-token privileges management
A vulnerability classified as critical has been found in SmarterTools SmarterMail. The impacted element is an unknown function of the file /api/v1/auth/refresh-token. This manipulation causes improper privilege management.
The identification of this vulnerability is CVE-2026-104084. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More