THREAT OPS › Threat News › [NVD] CVE-2026-23760 (CRITICAL 9.8) — SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administra
[NVD] CVE-2026-23760 (CRITICAL 9.8) — SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administra
CVE-2026-23760 CVSS: 9.8 CRITICAL Published: 2026-01-22T15:16:55.120
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supp
Indicators of compromise
- CVE-2026-23760cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-23760