References https://labs.watchtowr.com/attackers-with-decompilers-strike-again-smartertools-smartermail-wt-2026-0001-auth-bypass/ https://cloud.tencent.com/developer/article/2631609 https://zhuanlan.zhihu.com/p/1997751124111942608 https://www.vulncheck.com/advisories/smartertools-smartermail-authentication-bypass-via-password-reset-api https://www.sentinelone.com/vulnerability-database/cve-2026-23760/ https://www.cyfirma.com/research/cve-2026-23760-smartertools-smartermail-authentication-bypass-vulnerability/ https://cloud.tencent.com/developer/article/2624365 https://nvd.nist.gov/vuln/detail/CVE-2026-23760 https://thehackernews.com/2026/01/smartermail-auth-bypass-exploited-in.html https://portal.smartertools.com/community/a97712/smartermail-administrator-password-reset-read-this-cve-2026-23760.aspx
Related VulnerabilitiesPoCCVE-2026-24423: SmarterMail - Remote Code ExecutionPoCSmarterMail ConnectToHub /api/v1/settings/sysadmin/connect-to-hub 命令执行漏洞(CVE-2026-24423)SmarterTools SmarterMail 远程代码执行漏洞(CVE-2026-24423)SmarterTools SmarterMail 权限管理不当漏洞PoCCVE-2026-23760: SmarterTools SmarterMail - Admin Password ResetPoCSmarterMail /api/v1/auth/force-reset-password 权限绕过漏洞SmarterMail 存在任意文件上传漏洞Smartertools Smartermail 未授权 文件上传限制不当漏洞PoCCVE-2025-52691: SmarterMail - Unrestricted File Upload