Authentication Bypass in SmarterMail Product by SmarterTools
CVE-2026-23760
Key Information:
- Vendor
Smartertools
- Status
- Vendor
- CVE Published:
- 22 January 2026
Badges
What is CVE-2026-23760?
An authentication bypass vulnerability exists in SmarterMail's password reset API, enabling unauthenticated attackers to reset administrator passwords without proper verification. This flaw allows attackers to submit a new password along with a target administrator username, facilitating unauthorized administrative access. SmarterTools has issued patches to address this security issue, emphasizing the urgency for users to upgrade their installations to prevent potential exploitation.
Affected Version(s)
SmarterMail 0 < 100.0.9511
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
