
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25067 is an unauthenticated path coercion vulnerability in SmarterTools SmarterMail affecting all builds prior to build 9518 (version 100.0.9518). The flaw exists in the background-of-the-day preview endpoint, where the application base64-decodes attacker-supplied input and uses it as a filesystem path without validation, enabling UNC path resolution on Windows systems. This causes the SmarterMail service to initiate outbound SMB authentication attempts to attacker-controlled hosts, enabling credential coercion and NTLM relay attacks. It was published on January 29, 2026, with a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 6.9 (Medium) (Red Hat CVE, VulnCheck Advisory).
The root cause is classified as CWE-706 (Use of Incorrectly-Resolved Name or Reference). The vulnerable endpoint accepts a base64-encoded value from an unauthenticated attacker, decodes it, and passes it directly to a filesystem path resolution function without sanitization or validation. On Windows, this allows an attacker to supply a UNC path (e.g., \\attacker-host\share) that causes the SmarterMail service account to initiate an outbound SMB connection, leaking NTLM credentials in the process. No authentication is required, and the attack can be executed remotely with low complexity (VulnCheck Advisory, Red Hat CVE).
Successful exploitation allows an unauthenticated remote attacker to coerce the SmarterMail Windows service into authenticating to an attacker-controlled SMB server, exposing the service account's NTLM credentials. These credentials can be captured and cracked offline or relayed in real time to authenticate to other internal systems (NTLM relay attacks), potentially enabling lateral movement within the network. While the CVSS v3.1 score reflects limited direct confidentiality and availability impact, the real-world risk is significantly elevated due to the potential for credential theft and network-wide compromise (VulnCheck Advisory, The Hacker News).
CVE-2026-25067 requires no authentication and no user interaction, making it trivially exploitable by any remote attacker. The EPSS score is approximately 0.026%, though reporting from multiple sources indicates that SmarterMail vulnerabilities disclosed in the same patch cycle have been actively exploited in ransomware attacks, with a CISA alert referenced in threat intelligence (ctrlaltnod.com). A VulnCheck advisory details the vulnerability mechanics, and the CVE was assigned by VulnCheck. No specific exploit kit attribution has been confirmed for this CVE specifically, but the broader SmarterMail vulnerability cluster has drawn active threat actor attention (VulnCheck Advisory, The Hacker News).
base64('\\<attacker-ip>\share')).\\).MailService.exe) initiating outbound network connections to SMB ports on external hosts.SmarterTools has released a fix in SmarterMail build 9518 (version 100.0.9518 and later); administrators should upgrade immediately (SmarterTools Release Notes). As a temporary workaround where patching is not immediately possible, network-level controls should be applied to block outbound SMB traffic (TCP/UDP port 445) from the SmarterMail server to prevent credential coercion and relay attacks. Additionally, configuring the SmarterMail service to run under a least-privilege account with no domain privileges will limit the impact of any captured credentials.
The Hacker News covered the SmarterMail patch release, highlighting the critical unauthenticated RCE flaws addressed in the same update cycle (The Hacker News). Security community discussion on forums such as GRC and Mastodon (infosec.exchange) noted the severity of the SmarterMail vulnerability cluster, with community members urging rapid patching (GRC Forums). Reports from ctrlaltnod.com and beyondmachines.net flagged active ransomware exploitation of SmarterMail vulnerabilities and a related CISA alert, elevating urgency for affected organizations (ctrlaltnod.com).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."