SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application.
Metrics
Affected Vendors & Products
References
History
Fri, 23 Jan 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application. | |
| Title | SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-23T18:35:39.728Z
Reserved: 2026-01-22T18:21:46.813Z
Link: CVE-2026-24423
No data.
Status : Received
Published: 2026-01-23T17:16:13.483
Modified: 2026-01-23T17:16:13.483
Link: CVE-2026-24423
No data.
OpenCVE Enrichment
No data.