CVE-2026-23760 is a critical authentication bypass vulnerability in SmarterTools SmarterMail versions prior to build 9511. An unauthenticated attacker can exploit a flaw in the password reset API to reset system administrator accounts, gaining full administrative control over the SmarterMail instance and potentially the underlying host with SYSTEM/root privileges. This vulnerability carries a CVSS score of 9.8 (CRITICAL) due to its low attack complexity and severe impact. It is actively exploited in the wild, including in known ransomware campaigns, with public Nuclei templates available and significant community discussion and media coverage confirming its rapid weaponization.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 100.0.9511CPE match | cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:* | ||
< 100.0.9511CPE matchmatch criteria | cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.