SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application.
Metrics
Affected Vendors & Products
References
History
Mon, 26 Jan 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Smartertools
Smartertools smartermail |
|
| Vendors & Products |
Smartertools
Smartertools smartermail |
Fri, 23 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 23 Jan 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application. | |
| Title | SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-01-23T16:53:34.951Z
Updated: 2026-01-24T04:55:34.292Z
Reserved: 2026-01-22T18:21:46.813Z
Link: CVE-2026-24423
Updated: 2026-01-23T18:35:36.880Z
Status : Awaiting Analysis
Published: 2026-01-23T17:16:13.483
Modified: 2026-01-26T15:03:33.357
Link: CVE-2026-24423
No data.