logo

SmarterMail auth bypass flaw now exploited to hijack admin accounts

ID: a8411d84-df55-5e22-91d2-eb2c18716ea7

STIX ID: report--a8411d84-df55-5e22-91d2-eb2c18716ea7

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-01-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

An authentication-bypass flaw in SmarterTools SmarterMail's publicly exposed force-reset-password API lets unauthenticated attackers set new passwords for admin accounts (via an IsSysAdmin JSON field), enabling admin takeover and SYSTEM-level remote code execution; researchers observed active exploitation soon after a patch was released and users are advised to upgrade to Build 9511.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.