CVE-2026-24423

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application.
CVSS

No CVSS.

Configurations

No configuration.

History

23 Jan 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-23 17:16

Updated : 2026-01-26 15:03


NVD link : CVE-2026-24423

Mitre link : CVE-2026-24423

CVE.ORG link : CVE-2026-24423


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function