• News/
  • https://www.bleepingcomputer.com/news/security/smartermail-auth-bypass-flaw-now-exploited-to-hijack-admin-accounts/

SmarterMail auth bypass flaw now exploited to hijack admin accounts

BleepingComputer
·
Bill Toulas
·
Published Jan 22, 2026
·
Updated

Hackers began exploiting an authentication bypass vulnerability in SmarterTools' SmarterMail email server and collaboration tool that allows resetting admin passwords. An authentication bypass vulnerability in SmarterTools SmarterMail, which allows unauthenticated attackers to reset the system administrator password and obtain full privileges, is now actively exploited in the wild. The issue resides in the force-reset-password API endpoint, which is intentionally exposed without authentication. Researchers at cybersecurity company watchTowr reported the issue on January 8, and SmarterMail released a fix on January 15 without an identifier being assigned. After the issue was addressed, the researchers found evidence that threat actors started to exploit it just two days later. This suggests that hackers reverse-engineered the patch and found a way to leverage the flaw. SmarterMail is a self-hosted Windows email server and collaboration platform developed by SmarterTools that provides SMTP/IMAP/POP email, webmail, calendars, contacts, and basic groupware features. It is typically used by managed service providers (MSPs), small and medium-sized businesses, and hosting providers offering email services. SmarterTools claims that its products have 15 million users in 120 countries. The CVE-less flaw arises from the API endpoint ‘force-reset-password’ accepting attacker-controlled JSON input, including a 'IsSysAdmin' bool type property, which, if set to ‘true,’ forces the backend t...

Read full article

Affected Software

1 affected component
SmarterTools SmarterMail<Build 9511
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses an authentication bypass vulnerability in SmarterMail that is being actively exploited to hijack admin accounts.

2

What security implications are discussed in the article?

The exploitation of the vulnerability allows attackers to reset admin passwords and take control of email servers.

3

What products or software are affected by the vulnerability?

The affected software is SmarterTools' SmarterMail, specifically versions up to Build 9511.

4

How are hackers exploiting this vulnerability?

Hackers are exploiting the flaw by bypassing authentication mechanisms to gain unauthorized access to admin accounts.

5

What should users of SmarterMail do in response to this vulnerability?

Users of SmarterMail should urgently update their software to the latest version to protect against this exploit.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203