THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-23760 (CRITICAL 9.8) — SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administra

[NVD] CVE-2026-23760 (CRITICAL 9.8) — SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administra

lownvdPublished 2026-01-22

CVE-2026-23760 CVSS: 9.8 CRITICAL Published: 2026-01-22T15:16:55.120

SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supp

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-23760