Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-24423

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.182
EPSS Ranking 95.0%
CVSS Severity
CVSS v3 Score 9.8
Proposed Action
SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a malicious HTTP server which serves the malicious OS command and could lead to command execution.
Ransomware Campaign
Known
Products affected by CVE-2026-24423


Contact Us

Shodan ® - All rights reserved