CVE-2026-23760: SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability
SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. This could allow an unauthenticated attacker to supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance.
Other sources
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance. NOTE: SmarterMail system administrator privileges grant the ability to execute operating system commands via built-in management functionality, effectively providing administrative (SYSTEM or root) access on the underlying host.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SmarterTools SmarterMailto a version that resolves this vulnerability.Fixed in build 9511 - Remove
Remove
SmarterTools SmarterMailfrom your environment.Discontinue use or uninstall the product if vendor mitigations are unavailable.
- Compensating control
Apply mitigations per vendor instructions and follow applicable BOD 22-01 guidance for cloud services.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23760?
CVE-2026-23760 is classified as a high-severity authentication bypass vulnerability in SmarterTools SmarterMail.
How do I fix CVE-2026-23760?
To fix CVE-2026-23760, upgrade SmarterTools SmarterMail to build 9511 or later.
What impact does CVE-2026-23760 have on my system?
CVE-2026-23760 allows attackers to reset passwords for any user without authentication, compromising account security.
Which versions of SmarterMail are affected by CVE-2026-23760?
SmarterTools SmarterMail versions prior to build 9511 are affected by CVE-2026-23760.
Is there a workaround for CVE-2026-23760?
There are no official workarounds for CVE-2026-23760; the recommended action is to upgrade to the fixed version.