SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance. NOTE: SmarterMail system administrator privileges grant the ability to execute operating system commands via built-in management functionality, effectively providing administrative (SYSTEM or root) access on the underlying host.
Is CVE-2026-23760 exploited?
Listed in the CISA KEV catalog on 2026-01-26.
Federal remediation due 2026-02-16.
Past that date by 180 days.
Used in ransomware campaigns.
EPSS puts exploitation in the next 30 days at 96%.
Public exploit code: none found in monitored sources.
Public detection rules exist.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2026-23760
PlainSec has not published a story about this CVE.