Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

Merlin, a common roadside duck in Mexico City, will be the World Cup mascot.

BTS is the group fans are most looking forward to seeing perform at the 2026 World Cup

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » SmarterMail authentication bypass exploited 2 days after patch release
Celebrities

SmarterMail authentication bypass exploited 2 days after patch release

By January 22, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Rabi LakshmananJanuary 22, 2026Vulnerabilities / Email Security

A new security flaw in SmarterTools SmarterMail email software is now being exploited in the wild two days after a patch was released.

This vulnerability currently does not have a CVE identifier and is tracked by watchTowr Labs as WT-2026-0001. Patched by SmarterTools with build 9511 on January 15, 2026 after responsible disclosure by exposure management platform on January 8, 2026.

This is described as an authentication bypass flaw that could allow arbitrary users to reset the password of a SmarterMail system administrator using a specially crafted HTTP request to the “/api/v1/auth/force-reset-password” endpoint.

“The problem, of course, is that users can run the OS directly with RCE functionality as a feature.” [operating system] command,” said watchTowr Labs researchers Piotr Bazydlo and Sina Kheirkhah.

The root of the issue lies in the “SmarterMail.Web.Api.AuthenticationController.ForceResetPassword” function, which not only allows the endpoint to be reached without authentication, but also handles incoming requests depending on whether the user is a system administrator or not, by taking advantage of the fact that the reset request is accompanied by a boolean flag called “IsSysAdmin.”

cyber security

If the flag is set to ‘true’ (i.e. indicating that the user is an administrator), the underlying logic performs the following set of actions:

Gets the settings corresponding to the username passed as input in the HTTP request. Create a new system administrator item with a new password. Update your administrator account with a new password.

In other words, Privileged Pass is configured to allow you to easily update an administrator user’s password by sending an HTTP request using the administrator account’s username and password of your choice. This complete lack of security control could be exploited by an attacker to gain elevated access if they knew the existing administrator’s username.

This is not the end. This is because authentication bypass provides a direct path to remote code execution through built-in functionality that allows system administrators to execute operating system commands on the underlying operating system and obtain a SYSTEM-level shell.

To do this, go to the “Settings” page, create a new volume, and enter any command in the “Volume mount command” field. This command is then executed by the host operating system.

The cybersecurity company said it decided to make its findings public following a post on the SmarterTools community portal. In the post, users claimed that logs showed that the same “force-reset-password” endpoint was used to change passwords on January 17, 2026, two days after the patch was released, leaving them unable to access their administrator accounts.

This may indicate that the attacker reverse-engineered the patch and reconstructed the flaw. To make matters worse, it doesn’t help that SmarterMail’s release notes are vague and don’t explicitly mention what issues have been resolved. One item in the bulleted list for build 9511 simply says “Important: Important security fixes.”

cyber security

In response, SmarterTools CEO Tim Uzzanti hinted that this was to avoid giving attackers further avenues of attack, but said that they plan to send an email whenever a new CVE is discovered, and again when a build is released that resolves the issue.

“In our 23-plus years, we have only had a few CVEs, and they were primarily communicated through release notes and critical fix references,” Uzzanti said in response to transparency concerns raised by customers. “We appreciate the feedback that will lead to future policy changes.”

It is currently unknown whether such an email was sent to SmarterMail administrators this time. Hacker News has reached out to SmarterTools for comment and will update the article if we hear back.

This development comes less than a month after the Cyber ​​Security Authority of Singapore (CSA) detailed a maximum severity security flaw in SmarterMail (CVE-2025-52691, CVSS score: 10.0) that could be exploited to remotely execute code.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleEU unveils digital networks law to enable future-proof connectivity
Next Article Malicious PyPI package impersonates SymPy and deploys XMRig Miner to Linux hosts

Related Posts

Duchess Kate wears Patrick McDowell bespoke with Order of the Garter

June 15, 2026

Melania Trump shows off her high fashion look in Dolce & Gabbana at UFC 250

June 15, 2026

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

Merlin, a common roadside duck in Mexico City, will be the World Cup mascot.

BTS is the group fans are most looking forward to seeing perform at the 2026 World Cup

Swimming Pole, Billboard’s Emerging Dance Artist of the Month

Trending Posts

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

June 16, 2026

BTS is the group fans are most looking forward to seeing perform at the 2026 World Cup

June 15, 2026

Swimming Pole, Billboard’s Emerging Dance Artist of the Month

June 15, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.