
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-52691 is a critical unrestricted file upload vulnerability (CWE-434) in SmarterTools SmarterMail that allows unauthenticated attackers to upload arbitrary files to any location on the mail server, potentially enabling remote code execution. It affects all SmarterMail versions prior to Build 100.0.9413 (including legacy Build 16.x up to 16.3.6989.16341). The vulnerability was first published on December 28–29, 2025, assigned by Singapore's Cyber Security Agency (CSA), and added to CISA's Known Exploited Vulnerabilities (KEV) catalog on January 26, 2026. It carries a CVSS v3.1 base score of 10.0 (Critical) (CSA Advisory, CISA KEV).
The root cause is an unrestricted file upload flaw (CWE-434) in SmarterMail's web interface that fails to validate or restrict file types and destination paths for uploaded content. Attackers exploit a path traversal condition in an unauthenticated endpoint to write arbitrary files — including ASPX web shells — to sensitive directories such as C:\Program Files (x86)\SmarterTools\SmarterMail\Service\App_Data (builds 94xx) or C:\Program Files (x86)\SmarterTools\SmarterMail\MRS\App_Data (build 16). No authentication, user interaction, or special privileges are required; the attack is fully network-accessible with low complexity. watchTowr researchers (Piotr @chudyPB and Sina Kheirkhah @SinSinology) published a detection artifact generator and technical write-up, and a separate authentication bypass (WT-2026-0001) was later disclosed that chains with this vulnerability for full account takeover leading to RCE (watchTowr PoC, watchTowr Blog).
Successful exploitation grants an unauthenticated remote attacker full control over the SmarterMail server, including the ability to execute arbitrary code as the mail service account, access all hosted email data, and use the compromised server as a pivot point for lateral movement within the network. The changed scope (S:C) in the CVSS vector reflects that impact extends beyond the mail application itself to the underlying host OS. Ransomware groups including Warlock (Storm-2603) and Medusa (Storm-1175) have leveraged this vulnerability to breach organizations, encrypt data, and extort victims (The Hacker News, Microsoft Blog, Huntress).
App_Data folder accessible via the web server).http://target/App_Data/shell.aspx) to execute arbitrary OS commands as the SmarterMail service account.../, ..\); outbound connections from the SmarterMail server to unknown external IPs; mass scanning activity targeting SmarterMail version enumeration endpoints..aspx files in C:\Program Files (x86)\SmarterTools\SmarterMail\Service\App_Data\ or C:\Program Files (x86)\SmarterTools\SmarterMail\MRS\App_Data\; newly created files with random names (e.g., epoyn5_0.aspx) in web-accessible directories; ransomware encryptor binaries or batch scripts dropped on the host..aspx files; Windows Event Logs showing new scheduled tasks or service installations by the SmarterMail service account.cmd.exe, powershell.exe, net.exe); w3wp.exe spawning command-line tools; unexpected aspnet_compiler.exe or csc.exe activity.SmarterTools released a patch in SmarterMail Build 100.0.9413; all installations running Build 9406 or earlier (including legacy Build 16.x) should be updated immediately (CISA KEV, SmarterTools Release Notes). As an interim workaround, implement network-level access controls to restrict internet-facing exposure of SmarterMail web interfaces to trusted IP ranges only. Monitor SmarterMail servers for suspicious file creation in App_Data directories and unexpected ASPX files. Conduct forensic analysis on potentially compromised systems to detect unauthorized file uploads or web shells before applying the patch. CISA's BOD 22-01 requires federal agencies to remediate by February 16, 2026.
Singapore's Cyber Security Agency (CSA) was the CVE assigner and issued an early alert (AL-2025-124), prompting rapid coverage from The Hacker News, BleepingComputer, TechRadar, and Security Affairs (CSA Advisory, The Hacker News). watchTowr researchers published a detailed technical write-up and PoC, noting the vulnerability was exploited in the wild just two days after a related patch was released (watchTowr Blog). Huntress documented real-world account takeover incidents leading to RCE, and Rapid7 added a Metasploit module with a wrap-up blog post (Huntress, Rapid7). The Warlock ransomware group notably breached SmarterTools itself through an unpatched SmarterMail server, generating significant media attention and community discussion on Reddit, Mastodon, and Bluesky (The Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."