Hackers began exploiting an authentication bypass vulnerability in SmarterTools' SmarterMail email server and collaboration tool that allows resetting admin passwords. An authentication bypass vulnerability in SmarterTools SmarterMail, which allows unauthenticated attackers to reset the system administrator password and obtain full privileges, is now actively exploited in the wild. The issue resides in the force-reset-password API endpoint, which is intentionally exposed without authentication. Researchers at cybersecurity company watchTowr reported the issue on January 8, and SmarterMail released a fix on January 15 without an identifier being assigned. After the issue was addressed, the researchers found evidence that threat actors started to exploit it just two days later. This suggests that hackers reverse-engineered the patch and found a way to leverage the flaw. SmarterMail is a self-hosted Windows email server and collaboration platform developed by SmarterTools that provides SMTP/IMAP/POP email, webmail, calendars, contacts, and basic groupware features. It is typically used by managed service providers (MSPs), small and medium-sized businesses, and hosting providers offering email services. SmarterTools claims that its products have 15 million users in 120 countries. The CVE-less flaw arises from the API endpoint ‘force-reset-password’ accepting attacker-controlled JSON input, including a 'IsSysAdmin' bool type property, which, if set to ‘true,’ forces the backend t...
SmarterMail auth bypass flaw now exploited to hijack admin accounts
BleepingComputer
·Bill Toulas
·Published Jan 22, 2026
·Updated
Affected Software
1 affected component
SmarterTools SmarterMail<Build 9511
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses an authentication bypass vulnerability in SmarterMail that is being actively exploited to hijack admin accounts.
2
What security implications are discussed in the article?
The exploitation of the vulnerability allows attackers to reset admin passwords and take control of email servers.
3
What products or software are affected by the vulnerability?
The affected software is SmarterTools' SmarterMail, specifically versions up to Build 9511.
4
How are hackers exploiting this vulnerability?
Hackers are exploiting the flaw by bypassing authentication mechanisms to gain unauthorized access to admin accounts.
5
What should users of SmarterMail do in response to this vulnerability?
Users of SmarterMail should urgently update their software to the latest version to protect against this exploit.