Vulnerability Intelligence Report
SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
CVE-2026-23760
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance. NOTE: SmarterMail system administrator privileges grant the ability to execute operating system commands via built-in management functionality, effectively providing administrative (SYSTEM or root) access on the underlying host.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.3
CRITICAL
EPSS Probability:96.27%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-288 ↗CWE-288 Authentication Bypass Using an Alternate Path or Channel
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| SmarterTools | SmarterMail | 0 < 100.0.9511 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
96.268%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VulnCheck · Bug Bounty Provider · USA |
| Reserved | 2026-01-15T18:42:20 |
| Published | 2026-01-22T14:35:17 |
| Last Updated | 2026-08-04T03:56:03 |
Community Chatter & Buzz