SmarterTools SmarterMail versions prior to build 9511...
Critical severity
Unreviewed
Published
Jan 22, 2026
to the GitHub Advisory Database
•
Updated Jan 27, 2026
Description
Published by the National Vulnerability Database
Jan 22, 2026
Published to the GitHub Advisory Database
Jan 22, 2026
Last updated
Jan 27, 2026
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance.
References