CRITICAL

CVE-2026-24423

Smartertools Smartermail 2026-01-23 CVSS v3.1
CVSS
9.8
KEV

Description

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application.

Summary dbcve.org

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. An unauthenticated attacker can trigger the application to fetch and execute malicious OS commands from a remote HTTP server controlled by the attacker, leading to complete system compromise.

Mitigation

Update SmarterMail to build 9511 or later to remediate this vulnerability. If immediate patching is not possible, network-segment or restrict access to the ConnectToHub API endpoint to prevent unauthenticated external access.

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

87.99%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE