Manage Password Changes for SmarterMail Build 9375
Idea shared by Howell Dell - 8/31/2026 at 8:43 AM
Locked
Declined
Because of CVE-2026-7807 APP Passwords, and 2FA Secrets may have been exposed thru a security issue with JSON files.

What this means all end users will be forced into APP Passwords, and 2FA change with SmarterMail Build 9375. When you setup 2FA then SmarterMail automatically turns on APP Passwords thus this represents logins for anyone using Outlook Classic, eM Client, Smart Phone eMail Clients, Tablet eMail Clients any eMail Client maybe FAX Machines and Firewalls to mention a few.

As an MSP, I know security is important and I have moved +85% of my customers using 2FA and App Passwords which is good. This seems like a bitter pill to swallow.

I would rather have this to be managed by me rather than forcing this to all customers at once as I have a 250 Mailbox License. What about folks who have 500 or 1000 Mailboxes. It would be awful to have all customers to try to call me at once.

Of course I would eMail everyone about this, however, I know lots of folks are simply going to be unable to help themselves.

I would like to see a feature to allow me to manage this in /interface/root#/sysadmin/password-requirements.


Derek Curtis Replied
Employee Post
I'll pass this along, Howell. Thanks for the suggestion.

That said, how would you propose to manage that?
Derek Curtis
CCO
SmarterTools Inc.
This need to be stronger than a suggestion... I have a 250 License and +85% of my customers using 2FA and App Passwords. This is going to be an awful process to get everyone updated with new passwords.

@Derek Curtis  (SmarterMail)
That said, how would you propose to manage that?

I would TURN off the mandatory 2FA Secrets and APP Password change.

Then upon login of any super admin you can flash a notice about this issue and have a super admin confirm their understanding of the risk. This is what SonicWALL had done after their breech after finding that Gen 6 Firewalls that had weaker security standard were upgraded to Gen 7.

Then you would have a specific JSON key/value pair for the MailBox "config" that indicates the new security scheme has been applied to a specific MailBox when the 2FA and AP Password has been changed. If the JSON key/value pair is missing or FALSE then the MailBox has NOT been updated. If if the value is TRUE then the MailBox was upgraded.

Then in /interface/root#/sysadmin/password-requirements you can have a TAB showing MailBoxes that are using the old "Security Scheme". In this way a System Administrator can easily determine who has to be upgraded over time.

This would works in the same way as "Password Violations" giving System Administrator time to manage the change. You can also send one a month or quarter alerts informing the System Administrator that they should be upgrading the MailBoxes. In this way we both get what we need -- SmarterTools has fixed the security issue and placed the responsibility at the feet of the System Administrator.

This is just one strategy. Another option could be you have an Enable / Disable feature in the installer to let the  System Administrator choose. The default could be to enable this feature with a double OPT IN!


Tim Uzzanti Replied
Employee Post

I have been responding directly to Howell's ticket regarding this issue, but he doesn't like my answers.

What Howell is not understanding is that we do not have the flexibility to make critical security fixes opt-in.

When the FBI or other organizations contact us about critical CVEs, we must explain exactly how we resolved them. This means the issue must be resolved when a customer updates, not at the customer's convenience.

If we tell them that a fix would inconvenience us or our customers, that simply doesn't fly. They expect critical security issues to be resolved immediately and without requiring additional action from the customer beyond updating the software.

It is our recommendation that you update your server immediately to protect both your server and your users. If you choose not to update, that is your choice. We are doing what we are obligated to do to address the security issue.

This topic and discussion are now closed.
Tim Uzzanti
CEO
SmarterTools Inc.