Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SmarterMail before build 9777 contains a privilege escalation vulnerability where JWT access and refresh tokens embed a role claim at issuance that is not revalidated against the account's current role when redeemed through POST /api/v1/auth/refresh-token. Attackers who capture a refresh token issued before an administrator demotion, or a demoted user whose session was not actively polling at the time of demotion, can replay the stale token to obtain a new access token retaining the higher-privilege role (such as DomainAdmin or SysAdmin) until natural token expiry. | |
| Title | SmarterMail < Build 9777 Stale JWT Role Claim Privilege Escalation via Refresh Token | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-09T15:08:23.453Z
Reserved: 2026-10-01T18:02:50.085Z
Link: CVE-2026-104084
No data.
Status : Received
Published: 2026-10-09T16:17:21.153
Modified: 2026-10-09T16:17:21.153
Link: CVE-2026-104084
No data.
OpenCVE Enrichment
No data.
-
CWE-613
Insufficient Session Expiration