← Back to CVE List
Vulnerability Intelligence Report
SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API

CVE-2026-23760

x_known-exploited-vulnerability

SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance. NOTE: SmarterMail system administrator privileges grant the ability to execute operating system commands via built-in management functionality, effectively providing administrative (SYSTEM or root) access on the underlying host.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
9.3
CRITICAL
EPSS Probability:96.27%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-288 ↗CWE-288 Authentication Bypass Using an Alternate Path or Channel

Affected Products & Versions

Vendor Product Affected Versions
SmarterTools SmarterMail 0 < 100.0.9511 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
96.268%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulnCheck · Bug Bounty Provider · USA
Reserved2026-01-15T18:42:20
Published2026-01-22T14:35:17
Last Updated2026-08-04T03:56:03

LINK COPIED TO CLIPBOARD