cvedb.io
CVE-2026-23760
CRITICAL · CVSS 9.8 ⚠ KEV — EXPLOITED
EPSS exploitation probability: 100%
⚠ Listed in the CISA Known Exploited Vulnerabilities catalog — actively exploited.
Published 2026-01-26 · Last modified 2026-08-04T05:16:38.160

Summary

SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance. NOTE: SmarterMail system administrator privileges grant the ability to execute operating system commands via built-in management functionality, effectively providing administrative (SYSTEM or root) access on the underlying host.

Affected products

SmarterTools — SmarterMail

Does this affect you?

Add your gear to cvedb and we'll alert you only when SmarterTools ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.