Known vulnerability record

CVE-2026-23760

SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability

Stable IDcve:CVE-2026-23760Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability

SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. This could allow an unauthenticated attacker to supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance.

Keep the signals separate

CVSS severitycriticalScore 9.3 · source VulnCheck
EPSS probability96.3%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-01-26
Ransomware useknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2026-01-22
CVE modified
2026-08-04
KEV date added
2026-01-26
Dataset fetched
2026-08-21T03:54:58.468Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.