CVE-2026-24423
Description
SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application.
Summary dbcve.org
SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. An unauthenticated attacker can trigger the application to fetch and execute malicious OS commands from a remote HTTP server controlled by the attacker, leading to complete system compromise.
Mitigation
Update SmarterMail to build 9511 or later to remediate this vulnerability. If immediate patching is not possible, network-segment or restrict access to the ConnectToHub API endpoint to prevent unauthenticated external access.