SmarterMail Build 9526

  • Saturday, 31st January, 2026
  • 22:03pm

Build 9526

  • Changed: Revised restrictions for file and folder name validation.
  • Fixed: [API] Users may be able to be impersonated by system administrators who do not have impersonation permissions.
  • Fixed: [HA] Password Reset CAPTCHA now works as expected.
  • Fixed: [HA] Refresh token fails length validation.
  • Fixed: A system administrator's password cannot be reset if they have 2FA enabled.
  • Fixed: Administrative logs indicate a password was successfully reset even when the reset failed.
  • Fixed: Birthdate showing wrong date with UTC +01:00 in Outlook (EAS) on Android.
  • Fixed: Multipart/alternative e-mails not rendering HTML correctly.
  • Fixed: POP Timing Attack on APOP MD5 Hash Comparison.
  • Security: Fixed a BIMI SSRF vulnerability.
  • Security: Fixed a scenario where CAPTCHA might not expire within alloted time.
  • Security: Fixed an issue where EWS can be used to spoof email addresses despite AuthMatch being set to email address.
  • Security: Fixed some API endpoints that had improper security scope
  • Security: Hardened JWT tokens.
  • Security: Hardened password reset tokens.
  • Security: Hardened Simpleauthcontroller.
  • Security: Removed Command Line Action from Routing Rules.
  • Security: Resolved a cross site issue with MAPI requests.
« Back