


Perceptive Security
SOC/SIEM Consultancy

SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to …
Published:
5 February 2026 at 00:00:00
Alert date:
5 February 2026 at 21:07:15
Source:
cisa.gov
Email & Messaging, Enterprise Applications
SmarterTools SmarterMail contains a missing authentication vulnerability in the ConnectToHub API method that could allow attackers to execute OS commands. The vulnerability enables attackers to point the SmarterMail instance to a malicious HTTP server that serves malicious OS commands, potentially leading to command execution on the affected system. This represents a critical security flaw that bypasses authentication controls for a critical function.
Technical details
Mitigation steps:
Affected products:
SmarterTools SmarterMail
Related links:
https://www.cve.org/CVERecord?id=CVE-2026-24423
https://www.smartertools.com/smartermail/release-notes/current
https://nvd.nist.gov/vuln/detail/CVE-2026-24423
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
