peter bassill · operator
$ cve CVE-2026-23760 JSON

CVE-2026-23760 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 96.5% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2026-02-16.

Description

SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance. NOTE: SmarterMail system administrator privileges grant the ability to execute operating system commands via built-in management functionality, effectively providing administrative (SYSTEM or root) access on the underlying host.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS96.54% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-288
On CISA KEVyes — remediate by 2026-02-16
Public exploitnone known
Published2026-01-22
Last modified2026-08-04

CISA KEV

NameSmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability
Added2026-01-26
Due2026-02-16
Vendor / productSmarterTools / SmarterMail
Ransomware useknown

Affected (1)

VendorProduct
smartertoolssmartermail

References

→ the Explorer  ·  watch your stack  ·  NVD