CVE-2026-23760: SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability
SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. This could allow an unauthenticated attacker to supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23760?
CVE-2026-23760 is classified as a high-severity authentication bypass vulnerability in SmarterTools SmarterMail.
How do I fix CVE-2026-23760?
To fix CVE-2026-23760, upgrade SmarterTools SmarterMail to build 9511 or later.
What impact does CVE-2026-23760 have on my system?
CVE-2026-23760 allows attackers to reset passwords for any user without authentication, compromising account security.
Which versions of SmarterMail are affected by CVE-2026-23760?
SmarterTools SmarterMail versions prior to build 9511 are affected by CVE-2026-23760.
Is there a workaround for CVE-2026-23760?
There are no official workarounds for CVE-2026-23760; the recommended action is to upgrade to the fixed version.