CVE-2026-23760 | SmarterTools SmarterMail up to 100.0.9510 Password Reset API authentication bypass (EUVD-2026-4143 / Nessus ID 297224)
A vulnerability classified as critical has been found in SmarterTools SmarterMail up to 100.0.9510. The impacted element is an unknown function of the component Password Reset API. Performing a manipulation results in authentication bypass using alternate channel.
This vulnerability is reported as CVE-2026-23760. The attack is possible to be carried out remotely. Moreover, an exploit is present.
It is recommended to upgrade the affected component.