CVE-2026-23760: listed in the CISA KEV catalog

CVE-2026-23760 · CVSS 9.8 CRITICAL · EPSS 96% · KEV 2026-01-26

SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance. NOTE: SmarterMail system administrator privileges grant the ability to execute operating system commands via built-in management functionality, effectively providing administrative (SYSTEM or root) access on the underlying host.

Is CVE-2026-23760 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2026-23760

PlainSec has not published a story about this CVE.

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-11.