CVE-2026-23760

Published Jan 22, 2026

Last updated a day ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-23760 is an authentication bypass vulnerability found in SmarterTools SmarterMail versions prior to build 9511. This flaw exists within the product's password reset API, specifically the `force-reset-password` endpoint, which permits anonymous requests. An unauthenticated attacker can exploit this vulnerability by supplying a target administrator's username and a new password. This action allows them to reset the administrator's account without prior authentication or verification of the existing password or a reset token, leading to a complete administrative compromise of the SmarterMail instance. The administrative access gained through this bypass can further enable the execution of operating system commands via SmarterMail's built-in management functionalities. This vulnerability has been actively exploited in the wild.

Description
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance. NOTE: SmarterMail system administrator privileges grant the ability to execute operating system commands via built-in management functionality, effectively providing administrative (SYSTEM or root) access on the underlying host.
Source
disclosure@vulncheck.com
NVD status
Analyzed
Products
smartermail

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability
Exploit added on
Jan 26, 2026
Exploit action due
Feb 16, 2026
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

disclosure@vulncheck.com
CWE-288

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

1

  1. 🚨 CRITICAL THREAT ALERT - Jan 27 🔴 React Server Components RCE (CVE-2025-55182) - ACTIVE EXPLOITATION 🔴 SmarterMail Auth Bypass (CVE-2026-23760) 🔴 Mozi botnet surge: 150+ C2 URLs ⚡ PATCH NOW: React apps, SmarterMail, MS Office #CyberSecurity #ThreatIntel #InfoSec

    @404LABSx

    27 Jan 2026

    141 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Top 5 Trending CVEs: 1 - CVE-2025-0072 2 - CVE-2026-23760 3 - CVE-2025-27237 4 - CVE-2024-37079 5 - CVE-2026-24061 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    27 Jan 2026

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Two SmarterMail vulns were added to CISA KEV. I checked current patch adoption: 8,550 instances are still vulnerable to CVE-2026-23760 (auth bypass via admin password reset), and 6,657 to CVE-2025-52691 (RCE via arbitrary file upload). Only 26% (4,051) are fully patched. https://

    @nekono_naha

    27 Jan 2026

    2446 Impressions

    2 Retweets

    8 Likes

    2 Bookmarks

    2 Replies

    1 Quote

  4. ‼️CISA has added 5 vulnerabilities to the KEV Catalog https://t.co/9idGUAHIKd CVE-2018-14634: Linux Kernel Integer Overflow Vulnerability CVE-2025-52691: SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-23760: SmarterTools

    @DarkWebInformer

    27 Jan 2026

    3068 Impressions

    8 Retweets

    29 Likes

    12 Bookmarks

    0 Replies

    0 Quotes

  5. Top 5 Trending CVEs: 1 - CVE-2025-62186 2 - CVE-2023-28206 3 - CVE-2026-21962 4 - CVE-2026-24061 5 - CVE-2026-23760 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    26 Jan 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations