Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
identity-authentication-vulnerabilityactively-exploited-vulnerabilitywidely-deployed-product-advisoryinternet-facing-service-vulnerability

Authentication Bypass and Password-Reset Flaws Enable Account Takeover in SmarterMail and Appsmith

Updated 3mo agoFirst seen Jan 22, 20262 sources

watchTowr Labs disclosed WT-2026-0001, an authentication bypass in SmarterTools SmarterMail that allows a user to reset the system administrator password via a password-reset mechanism and then leverage SmarterMail’s built-in “RCE-as-a-feature” capabilities to execute OS commands. The researcher reported the issue and stated it was patched quickly, citing a fixed release on SmarterMail release 9511 (2026-01-15); the publication was accelerated after a tip that attackers were actively exploiting the flaw to reset admin passwords, with forum-shared logs reportedly showing suspicious activity tied to the force-reset-password endpoint.

Resecurity reported exploitation of CVE-2026-22794 in Appsmith, a critical authentication weakness in the password reset flow where the application trusts a client-controlled Origin header to build reset links. An attacker can initiate a reset for a victim while supplying a malicious Origin so the victim’s email contains a link to attacker infrastructure; when clicked, the reset token is exposed, enabling password change and full account takeover. Resecurity identified the affected endpoint as /api/v1/users/forgotPassword, stated Appsmith ≤ 1.92 is affected, and that the issue is fixed in Appsmith ≥ 1.93.

Share:
Authentication Bypass and Password-Reset Flaws Enable Account Takeover in SmarterMail and Appsmith
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Jan 21, 20265mo ago

Appsmith 1.93 identified as fix for CVE-2026-22794

The Resecurity report states that Appsmith versions up to and including 1.92 are affected, while version 1.93 and later contain the fix. Users were advised to upgrade and enforce a trusted base URL to prevent malicious reset-link generation.

Resecurity reports active exploitation and publishes Appsmith PoC

Resecurity said CVE-2026-22794 was being actively exploited and published proof-of-concept steps plus a Nuclei template showing token theft through the /api/v1/users/forgotPassword endpoint. The report also noted internet-exposed Appsmith instances and recommended upgrading and hardening reverse proxies or WAFs.

Appsmith flaw enables account takeover via Origin header manipulation

Resecurity disclosed CVE-2026-22794, a critical flaw in Appsmith's password reset and email verification flow that trusts the client-controlled HTTP Origin header when generating links. An attacker can cause a legitimate reset email to send victims to an attacker-controlled domain, capture the reset token, and take over the account.

Anonymous tip alerts researchers to likely SmarterMail exploitation

By January 21, watchTowr said it had received an anonymous tip pointing to exploitation activity against the SmarterMail vulnerability. The report connected this tip with earlier forum evidence to support concerns of real-world abuse.

Jan 15, 20265mo ago

Forum post suggests in-the-wild exploitation of SmarterMail flaw

A SmarterMail forum thread cited by watchTowr indicated possible active exploitation, including log evidence referencing the /api/v1/auth/force-reset-password endpoint shortly after the patch became available. This suggested attackers may have been exploiting or probing vulnerable systems rapidly after patch release.

SmarterTools releases SmarterMail 9511 to fix admin reset flaw

SmarterTools released SmarterMail version 9511, which added validation checks to the sysadmin password reset path and blocked the exploit path with an "Invalid input parameters" response. This version is identified as the vendor patch for WT-2026-0001.

Jan 8, 20266mo ago

watchTowr discovers and reports SmarterMail auth bypass to vendor

watchTowr identified WT-2026-0001 in SmarterTools SmarterMail, an authentication bypass that lets an unauthenticated attacker reset the system administrator password via /api/v1/auth/force-reset-password. The researchers reported the issue to the vendor on the same day.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

7 LINKEDOpen in app
Affected products
2 linked
SmartermailAppsmith
Organizations
3 linked
SmartertoolsWatchTowrResecurity
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Authentication Bypass and Password-Reset Flaws Enable Account Takeover in SmarterMail and Appsmith | Mallory