CVE-2026-23760

Published Jan 22, 2026

Last updated 3 months ago

Exploit knownCVSS critical 9.3
SmarterTools SmarterMail
API
Server
SMTP

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-23760 is an authentication bypass vulnerability found in SmarterTools SmarterMail versions prior to build 9511. This flaw exists within the product's password reset API, specifically the `force-reset-password` endpoint, which permits anonymous requests. An unauthenticated attacker can exploit this vulnerability by supplying a target administrator's username and a new password. This action allows them to reset the administrator's account without prior authentication or verification of the existing password or a reset token, leading to a complete administrative compromise of the SmarterMail instance. The administrative access gained through this bypass can further enable the execution of operating system commands via SmarterMail's built-in management functionalities. This vulnerability has been actively exploited in the wild.

Description
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance. NOTE: SmarterMail system administrator privileges grant the ability to execute operating system commands via built-in management functionality, effectively providing administrative (SYSTEM or root) access on the underlying host.
Source
disclosure@vulncheck.com
NVD status
Analyzed
Products
smartermail

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability
Exploit added on
Jan 26, 2026
Exploit action due
Feb 16, 2026
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

disclosure@vulncheck.com
CWE-288

Social media

Hype score
Not currently trending
  1. THREAT ALERT: Storm-1175 Blitz China-linked group weaponizing zero-days in SmarterMail (CVE-2026-23760) & GoAnywhere (CVE-2025-10035) for Medusa Ransomware. ⏱️ Speed: <24hrs to encrypt 🎯 Target: Edge assets (VPN/Mail) 🛡️ Action: Patch NOW #CyberSecurity #Zero

    @swapnil_mengi

    7 Apr 2026

    109 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Storm-1175 exploited zero-day vulnerabilities CVE-2025-10035 and CVE-2026-23760 to deploy Medusa ransomware within 24 hours of initial compromise. The China-based group rapidly escalated privileges, moved laterally through credential theft, and exfiltrated data before encryption.

    @aviatrixtrc

    7 Apr 2026

    150 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 Threat Alert: Medusa ransomware campaigns (Storm-1175 / Medusa affiliates) 📅 Date: 2026-04-06 📆 Timeline: Medusa RaaS tracked since 2023; Storm-1175 rapidly weaponized N-days and multiple zero-days (e.g., CVE-2026-23760 SmarterMail, CVE-2025-10035 GoAnywhere MFT) acr

    @syedaquib77

    6 Apr 2026

    145 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. BREAKING: Microsoft links China-based Storm-1175 to Medusa ransomware campaigns exploiting 16+ vulns including CVE-2025-10035 and CVE-2026-23760, hitting 300+ critical infrastructure orgs. https://t.co/x801FvMvlK

    @threatcluster

    6 Apr 2026

    117 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Cloudflare has released new WAF rules addressing the following CVEs to enhance customer protection. SmarterMail - Arbitrary File Upload (CVE-2025-52691) SmarterMail - Authentication Bypass (CVE-2026-23760) https://t.co/PZnybPuWA1

    @Cloudforce_One

    4 Mar 2026

    499 Impressions

    0 Retweets

    6 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  6. The following vulnerabilities have been added to our feed: - CVE-2025-49113: Roundcube PHP Object Deserialization RCE - CVE-2025-52691: SmarterMail Arbitrary File Upload RCE - CVE-2026-23760: SmarterMail Authentication Bypass RCE https://t.co/Nw6eZdt4CA

    @crowdfense

    19 Feb 2026

    622 Impressions

    1 Retweet

    5 Likes

    5 Bookmarks

    1 Reply

    0 Quotes

  7. Top 5 Trending CVEs: 1 - CVE-2026-20841 2 - CVE-2026-23760 3 - CVE-2026-21508 4 - CVE-2024-27834 5 - CVE-2026-21514 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    12 Feb 2026

    117 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 CISA Adds Exploited Microsoft Office, Linux Kernel, Telnetd, and SmarterMail Flaws to KEV — Feb 16 Patch Deadline CISA added five vulnerabilities (CVE-2026-21509, CVE-2018-14634, CVE-2026-24061, CVE-2025-52691, CVE-2026-23760) to the KEV catalog, requiring U.S. federal

    @ThreatSynop

    29 Jan 2026

    155 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 CRITICAL THREAT ALERT - Jan 27 🔴 React Server Components RCE (CVE-2025-55182) - ACTIVE EXPLOITATION 🔴 SmarterMail Auth Bypass (CVE-2026-23760) 🔴 Mozi botnet surge: 150+ C2 URLs ⚡ PATCH NOW: React apps, SmarterMail, MS Office #CyberSecurity #ThreatIntel #InfoSec

    @404LABSx

    27 Jan 2026

    141 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Top 5 Trending CVEs: 1 - CVE-2025-0072 2 - CVE-2026-23760 3 - CVE-2025-27237 4 - CVE-2024-37079 5 - CVE-2026-24061 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    27 Jan 2026

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Two SmarterMail vulns were added to CISA KEV. I checked current patch adoption: 8,550 instances are still vulnerable to CVE-2026-23760 (auth bypass via admin password reset), and 6,657 to CVE-2025-52691 (RCE via arbitrary file upload). Only 26% (4,051) are fully patched. https://

    @nekono_naha

    27 Jan 2026

    2446 Impressions

    2 Retweets

    8 Likes

    2 Bookmarks

    2 Replies

    1 Quote

  12. ‼️CISA has added 5 vulnerabilities to the KEV Catalog https://t.co/9idGUAHIKd CVE-2018-14634: Linux Kernel Integer Overflow Vulnerability CVE-2025-52691: SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-23760: SmarterTools

    @DarkWebInformer

    27 Jan 2026

    3068 Impressions

    8 Retweets

    29 Likes

    12 Bookmarks

    0 Replies

    0 Quotes

  13. Top 5 Trending CVEs: 1 - CVE-2025-62186 2 - CVE-2023-28206 3 - CVE-2026-21962 4 - CVE-2026-24061 5 - CVE-2026-23760 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    26 Jan 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations