Description
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance. NOTE: SmarterMail system administrator privileges grant the ability to execute operating system commands via built-in management functionality, effectively providing administrative (SYSTEM or root) access on the underlying host.
INFO
Published Date :
2026-01-22T14:35:17.235Z
Last Modified :
2026-03-05T01:30:23.457Z
Source :
VulnCheck
AFFECTED PRODUCTS
The following products are affected by CVE-2026-23760 vulnerability.
| Vendors | Products |
|---|---|
| Smartertools |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-23760.