Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-23760

Опубликовано: 22 янв. 2026
Источник: nvd
CVSS3: 9.8
EPSS Критический

Описание

SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance. NOTE: SmarterMail system administrator privileges grant the ability to execute operating system commands via built-in management functionality, effectively providing administrative (SYSTEM or root) access on the underlying host.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:*
Версия до 100.0.9511 (исключая)

EPSS

Процентиль: 100%
0.96268
Критический

9.8 Critical

CVSS3

Дефекты

CWE-288

Связанные уязвимости

CVSS3: 9.8
github
7 месяцев назад

SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance.

CVSS3: 9.8
fstec
7 месяцев назад

Уязвимость прикладного программного интерфейса force-reset-password почтового сервера SmarterTools SmarterMail, позволяющая нарушителю обновить пароль администратора до значения по умолчанию и получить несанкционированный доступ к серверу

EPSS

Процентиль: 100%
0.96268
Критический

9.8 Critical

CVSS3

Дефекты

CWE-288