Executive brief
SmarterMail, a popular enterprise email and collaboration server, contains a critical security flaw that allows unauthorized individuals to take over administrator accounts. By exploiting a weakness in the password reset system, an attacker can change the administrator's password without any existing credentials or special access. This grants the attacker full control over the email server, including the ability to read all user emails and execute commands on the underlying server hardware.
Technical details
An authentication bypass vulnerability (CWE-288) exists in the SmarterMail password reset API, specifically within the 'force-reset-password' endpoint. This endpoint permits anonymous requests and fails to validate an existing password or a valid reset token when targeting system administrator accounts. A remote, unauthenticated attacker can exploit this by submitting a target administrator username and a new password to the vulnerable endpoint. Successful exploitation results in full administrative compromise of the SmarterMail instance, which further allows for Remote Code Execution (RCE) with SYSTEM or root privileges via built-in management features. The vulnerability is addressed in SmarterMail build 9511.
Affected products
- SmarterTools SmarterMail Prior to build 9511
Timeline
- 2026-01-23: disclosed: Initial vulnerability details published by VulnCheck and researchers.
- 2026-01-26: kev added: CISA added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog.
- 2026-01-26: exploited: Vulnerability confirmed to be exploited in the wild.