A new security vulnerability in SmarterTools ' SmarterMail email software has begun to be actively exploited, two days after a patch was released. The vulnerability, tracked by watchTowr Labs as WT-2026-0001 , was patched by SmarterTools on January 15, 2026, following a responsible disclosure by the exposure management platform on January 8, 2026. It is described as an authentication bypass vulnerability that could allow any user to reset the SmarterMail system administrator password via a specially crafted HTTP request to the “ /api/v1/auth/force-reset-password “ endpoint.
See also: FortiGate: Automated attacks change firewall settings

Researchers from watchTowr Labs noted that the vulnerability allows users to execute operating system commands directly. The issue is located in the function “SmarterMail.Web.Api.AuthenticationController.ForceResetPassword,” which allows access to the endpoint without authentication and uses a logical flag named “IsSysAdmin” to determine whether the user is a system administrator.
If the flag is set to “true,” the following actions are performed:
1. Retrieve the configuration for the username provided in the HTTP request.
2. Create a new system administrator account with the new password.
3. Update the administrator account with the new password.
See also: Microsoft: Incorrect email routing enables internal domain phishing

This lack of security control allows an attacker to gain elevated access by knowing an existing administrator username. In addition, the authentication bypass allows remote code execution via a feature that allows a system administrator to execute operating system commands, leading to a SYSTEM-level shell.
The cybersecurity firm made the finding public after a user on the SmarterTools Community Portal reported losing access to their administrator account, with logs showing the use of the “force-reset-password” endpoint to change the password on January 17, 2026, shortly after the patch was released. This suggests that attackers may have reversed the patches to exploit the vulnerability.
SmarterMail's release notes were criticized for their vagueness, stating only "IMPORTANT: Critical security fixes" without providing details on the specific issues addressed. In response, SmarterTools CEOTim Uzzantisaid the company aims to avoid providing more information to malicious actors, but plans to notify administrators via email whenever a new CVE is discovered and when a release is released to address the issue.
See also: Critical vulnerability in SmarterMail allows attackers to execute remote code

It remains unclear whether such an email was sent to SmarterMail administrators regarding this vulnerability.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
