CVE-2026-7807
Last modified
CVE-2026-7807 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint that allows authenticated users to read arbitrary .json files on the system. Attackers can exploit this vulnerability combined with weak encryption algorithms and hardcoded keys to decrypt and access stored passwords and 2FA secrets for all users.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint that allows authenticated users to read arbitrary .json files on the system. Attackers can exploit this vulnerability combined with weak encryption algorithms and hardcoded keys to decrypt and access stored passwords and 2FA secrets for all users.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Smartertools | Smartermail | < 100.0.9560 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-7807?
How severe is CVE-2026-7807?
How do I fix CVE-2026-7807?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-78061A vulnerability was determined in vas3k TaxHacker up to 0.8.…6.3
- CVE-2026-78062A vulnerability was identified in vas3k TaxHacker up to 0.8.…7.3
- CVE-2026-78063A security flaw has been discovered in Tenda CH22 1.0.0.1. T…7.4
- CVE-2026-78064Joomla Extension - j2commerce.com - Anonymous cart-record ta…8.8
- CVE-2026-78065Joomla Extension - j2commerce.com - Guest checkout address d…7.1
- CVE-2026-78069Joomla Extension - j2commerce.com - Missing authorization on…9.5
- CVE-2026-78070Joomla Extension - digital-peak.com - Authenticated, privile…6.9
- CVE-2026-78071Joomla Extension - digital-peak.com - Authenticated, privile…7.5
- CVE-2026-78072Joomla Extension - Jefferson49 - Unauthenticated blind SQLi …8.7
- CVE-2026-78073Joomla Extension - mrvinoth.com - Reflected XSS in All Video…5.3
- CVE-2026-78074Joomla Extension - miniorgange.com - Unauthenticated arbitra…8.8
- CVE-2026-78075Joomla Extension - joomshaper.com - Broken Object-Level Auth…5.1
Are you affected by CVE-2026-7807?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
