Vulnerability Description
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance. NOTE: SmarterMail system administrator privileges grant the ability to execute operating system commands via built-in management functionality, effectively providing administrative (SYSTEM or root) access on the underlying host.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Smartertools | Smartermail | < 100.0.9511 |
Related Weaknesses (CWE)
References
- https://code-white.com/public-vulnerability-list/#authenticationserviceforcereseThird Party Advisory
- https://labs.watchtowr.com/attackers-with-decompilers-strike-again-smartertools-ExploitThird Party Advisory
- https://www.smartertools.com/smartermail/release-notes/currentRelease Notes
- https://www.vulncheck.com/advisories/smartertools-smartermail-authentication-bypThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-US Government Resource
- https://www.huntress.com/blog/smartermail-account-takeover-leading-to-rceExploitThird Party Advisory
FAQ
What is CVE-2026-23760?
CVE-2026-23760 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails t...
How severe is CVE-2026-23760?
CVE-2026-23760 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-23760?
Check the references section above for vendor advisories and patch information. Affected products include: Smartertools Smartermail.