SmarterTools SmarterMail - Admin Password Reset
CVE-2026-23760
Verified
Description
Detected a SmartMail admin password reset vulnerability by sending a POST request to the `/api/v1/auth/force-reset-password` endpoint, indicating that administrative password resets could potentially be triggered without proper authorization.
Severity
Critical
Published Date
January 22, 2026
Template Author
watchtowr, dhiyaneshdk
CVE-2026-23760.yaml
9.5Severity
CVSS Metrics
Remediation Steps
Upgrade to build 9511 or later.