Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Anduril has invented a novel drone flying contest where work is the prize

Bluesky previews 2026 roadmap: Discover feed, real-time features, and more improvements

Anthropic and OpenAI CEOs condemn ICE violence, praise Trump

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » SmarterMail authentication bypass exploited 2 days after patch release
Identity

SmarterMail authentication bypass exploited 2 days after patch release

userBy userJanuary 22, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Rabi LakshmananJanuary 22, 2026Vulnerabilities / Email Security

A new security flaw in SmarterTools SmarterMail email software is now being exploited in the wild two days after a patch was released.

This vulnerability currently does not have a CVE identifier and is tracked by watchTowr Labs as WT-2026-0001. Patched by SmarterTools with build 9511 on January 15, 2026 after responsible disclosure by exposure management platform on January 8, 2026.

This is described as an authentication bypass flaw that could allow arbitrary users to reset the password of a SmarterMail system administrator using a specially crafted HTTP request to the “/api/v1/auth/force-reset-password” endpoint.

“The problem, of course, is that users can run the OS directly with RCE functionality as a feature.” [operating system] command,” said watchTowr Labs researchers Piotr Bazydlo and Sina Kheirkhah.

The root of the issue lies in the “SmarterMail.Web.Api.AuthenticationController.ForceResetPassword” function, which not only allows the endpoint to be reached without authentication, but also handles incoming requests depending on whether the user is a system administrator or not, by taking advantage of the fact that the reset request is accompanied by a boolean flag called “IsSysAdmin.”

cyber security

If the flag is set to ‘true’ (i.e. indicating that the user is an administrator), the underlying logic performs the following set of actions:

Gets the settings corresponding to the username passed as input in the HTTP request. Create a new system administrator item with a new password. Update your administrator account with a new password.

In other words, Privileged Pass is configured to allow you to easily update an administrator user’s password by sending an HTTP request using the administrator account’s username and password of your choice. This complete lack of security control could be exploited by an attacker to gain elevated access if they knew the existing administrator’s username.

This is not the end. This is because authentication bypass provides a direct path to remote code execution through built-in functionality that allows system administrators to execute operating system commands on the underlying operating system and obtain a SYSTEM-level shell.

To do this, go to the “Settings” page, create a new volume, and enter any command in the “Volume mount command” field. This command is then executed by the host operating system.

The cybersecurity company said it decided to make its findings public following a post on the SmarterTools community portal. In the post, users claimed that logs showed that the same “force-reset-password” endpoint was used to change passwords on January 17, 2026, two days after the patch was released, leaving them unable to access their administrator accounts.

This may indicate that the attacker reverse-engineered the patch and reconstructed the flaw. To make matters worse, it doesn’t help that SmarterMail’s release notes are vague and don’t explicitly mention what issues have been resolved. One item in the bulleted list for build 9511 simply says “Important: Important security fixes.”

cyber security

In response, SmarterTools CEO Tim Uzzanti hinted that this was to avoid giving attackers further avenues of attack, but said that they plan to send an email whenever a new CVE is discovered, and again when a build is released that resolves the issue.

“In our 23-plus years, we have only had a few CVEs, and they were primarily communicated through release notes and critical fix references,” Uzzanti said in response to transparency concerns raised by customers. “We appreciate the feedback that will lead to future policy changes.”

It is currently unknown whether such an email was sent to SmarterMail administrators this time. Hacker News has reached out to SmarterTools for comment and will update the article if we hear back.

This development comes less than a month after the Cyber ​​Security Authority of Singapore (CSA) detailed a maximum severity security flaw in SmarterMail (CVE-2025-52691, CVSS score: 10.0) that could be exploited to remotely execute code.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleEU unveils digital networks law to enable future-proof connectivity
Next Article Malicious PyPI package impersonates SymPy and deploys XMRig Miner to Linux hosts
user
  • Website

Related Posts

WhatsApp deploys lockdown-style security mode to protect targeted users from spyware

January 27, 2026

Experts detect Pakistan-linked cyber attack targeting Indian government agencies

January 27, 2026

ClickFix attack spreads using fake CAPTCHAs, Microsoft Scripts, and trusted web services

January 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Anduril has invented a novel drone flying contest where work is the prize

Bluesky previews 2026 roadmap: Discover feed, real-time features, and more improvements

Anthropic and OpenAI CEOs condemn ICE violence, praise Trump

Android smartphones are getting more anti-theft features

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.