SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability
High Listed in CISA KEV
Summary
SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. This could allow an unauthenticated attacker to supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- SmarterTools:SmarterMail
Sources
- CISA KEV DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2026-23760 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://www.smartertools.com/smartermail/release-notes/current reference
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV