CRITICAL

CVE-2026-23760

Smartertools Smartermail 2026-01-22 CVSS v3.1
CVSS
9.8
KEV

Description

SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance. NOTE: SmarterMail system administrator privileges grant the ability to execute operating system commands via built-in management functionality, effectively providing administrative (SYSTEM or root) access on the underlying host.

Summary dbcve.org

SmarterMail versions before build 9511 have an authentication bypass in the password reset API. The force-reset-password endpoint accepts anonymous requests and does not validate the existing password or reset token when resetting system administrator accounts. An unauthenticated attacker can reset any admin account password by specifying the username and new password, achieving full administrative access. Since SmarterMail system administrators can execute OS commands through built-in management features, this vulnerability provides SYSTEM/root-level access on the host.

Mitigation

Upgrade SmarterMail to build 9511 or later to remediate this vulnerability. If immediate upgrading is not possible, restrict network access to the affected API endpoints as a temporary mitigation while planning the upgrade.

Proof of Concept

Weakness (CWE)

CWE-288

EPSS Score

96.54%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE