CVE-2026-24423

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application.
Configurations

Configuration 1 (hide)

cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:23

Type Values Removed Values Added
Summary
  • (es) Las versiones de SmarterTools SmarterMail anteriores a la compilación 9511 contienen una vulnerabilidad de ejecución remota de código no autenticada en el método API ConnectToHub. El atacante podría dirigir SmarterMail al servidor HTTP malicioso, que sirve el comando malicioso del sistema operativo. Este comando será ejecutado por la aplicación vulnerable.

06 Feb 2026, 16:45

Type Values Removed Values Added
CPE cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Smartertools
Smartertools smartermail
References () https://code-white.com/public-vulnerability-list/#systemadminsettingscontrollerconnecttohub-missing-authentication-in-smartermail - () https://code-white.com/public-vulnerability-list/#systemadminsettingscontrollerconnecttohub-missing-authentication-in-smartermail - Third Party Advisory
References () https://www.smartertools.com/smartermail/release-notes/current - () https://www.smartertools.com/smartermail/release-notes/current - Release Notes
References () https://www.vulncheck.com/advisories/smartertools-smartermail-unauthenticated-rce-via-connecttohub-api - () https://www.vulncheck.com/advisories/smartertools-smartermail-unauthenticated-rce-via-connecttohub-api - Third Party Advisory
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-24423 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-24423 - US Government Resource

05 Feb 2026, 21:15

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-24423 -

23 Jan 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-23 17:16

Updated : 2026-06-17 10:23


NVD link : CVE-2026-24423

Mitre link : CVE-2026-24423

CVE.ORG link : CVE-2026-24423


JSON object : View

Products Affected

smartertools

  • smartermail
CWE
CWE-306

Missing Authentication for Critical Function