CWE-CWE-288

SmarterTools SmarterMail Admin Password Reset (CVE-2026-23760)

Severity:
Critical
Summary
SmarterTools SmarterMail contains an unauthenticated administrative password reset vulnerability. The application exposes an API endpoint that accepts password reset requests without verifying a secret. By sending a crafted POST request with a target username and desired password, a remote unauthenticated attacker can overwrite the administrator's credentials, gaining full control over the mail server administration interface.
Impact
An unauthenticated attacker can fully compromise the SmarterMail by resetting the administrator password.
Remediation
Upgrade SmarterMail to the latest patched version and ensure all security updates are applied regularly.
Required Skills for Successful Exploitation
Actions To Take
Classifications
Vulnerability Index

You can search and find all vulnerabilities

Featured resources

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding