CVE-2026-23760
SmarterMail versions before build 9511 have an authentication bypass in the password reset API. The force-reset-password endpoint allows anyone to reset an administrator’s password without authentication. This gives an attacker full administrative control of the mail server.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
SmarterTools SmarterMail users running any build prior to 9511, especially those who have system administrator accounts.
Real-world impact
An attacker can reset an administrator’s password, gain full administrative privileges, and execute operating‑system commands on the host, effectively obtaining root or SYSTEM access.
Why this severity
The CVSS score of 9.3 reflects the vulnerability’s high impact (full admin takeover and OS command execution) combined with low attack complexity, no authentication, and no user interaction required.
What to do about it
- 01Apply the vendor-provided mitigation as described in SmarterMail’s official advisory.
CISA KEV required action
Timeline
- Jan 22, 2026 · Jan 22, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jan 26, 2026 · Jan 26, 2026Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Feb 16, 2026 · Feb 16, 2026CISA remediation deadlineFederal agencies are required to remediate by this date.
- Aug 4, 2026 · 1d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- code-white.com/public-vulnerability-list/third party advisory
- labs.watchtowr.com/attackers-with-decompilers-…exploitthird party advisory
- smartertools.com/smartermail/release-notes/c…release notes
- vulncheck.com/advisories/smartertools-sma…third party advisory
- cisa.gov/known-exploited-vulnerabili…us government resource
- huntress.com/blog/smartermail-account-ta…exploitthird party advisory