SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability
Critical CVSS 9.8 Listed in CISA KEV
Summary
SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. This could allow an unauthenticated attacker to supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- SmarterTools:SmarterMail
- :
Sources
- CISA KEV DATABASE
- NVD DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2026-23760 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://www.smartertools.com/smartermail/release-notes/current reference
- https://code-white.com/public-vulnerability-list/#authenticationserviceforceresetpassword-missing-authentication-in-smartermail Third Party Advisory
- https://labs.watchtowr.com/attackers-with-decompilers-strike-again-smartertools-smartermail-wt-2026-0001-auth-bypass/ Exploit
- https://www.vulncheck.com/advisories/smartertools-smartermail-authentication-bypass-via-password-reset-api Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-23760 US Government Resource
- https://www.huntress.com/blog/smartermail-account-takeover-leading-to-rce Exploit
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV
- nvd_ingest NVD