#VU122427 Use of incorrectly-resolved name or reference in SmarterMail - CVE-2026-25067
Published: February 6, 2026
SmarterMail
SmarterTools Inc.
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to a path coercion in the background-of-the-day preview endpoint when the application encodes untrusted input and uses it as a filesystem path without validation. A remote attacker can force the application to initiate outbound SMB authentication attempts to attacker-controlled servers and obtain NTLM hash that can be used later in NTLM relay attacks.