---
id: CVE-2026-24423
title: >-
  SmarterTools SmarterMail versions prior to build 9511 contain an
  unauthenticated remote code execution vulnerability in the ConnectToHub API
  method
summary: >-
  SmarterTools SmarterMail versions prior to build 9511 contain an
  unauthenticated remote code execution vulnerability in the ConnectToHub API
  method. The attacker could point the SmarterMail to the malicious HTTP server,
  which serves the …
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-306
vendor: smartertools
product: smartermail
affected:
  - smartermail < 100.0.9511
patched:
  - smartermail 100.0.9511
published: '2026-01-23'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-24423'
references:
  - url: >-
      https://code-white.com/public-vulnerability-list/#systemadminsettingscontrollerconnecttohub-missing-authentication-in-smartermail
    label: disclosure@vulncheck.com
  - url: 'https://www.smartertools.com/smartermail/release-notes/current'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/smartertools-smartermail-unauthenticated-rce-via-connecttohub-api
    label: disclosure@vulncheck.com
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-24423
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.88177
epssPercentile: 0.99765
kev: true
kevDateAdded: '2026-02-05'
kevDueDate: '2026-02-26'
kevRansomware: true
exploited: true
ingestedAt: '2026-08-04T05:36:13.475Z'
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/aavamin/CVE-2026-24423'
    - 'https://github.com/CyberAlp0/SmarterMail-CVE-2026-24423'
  nuclei:
    - CVE-2026-24423
  checkedAt: '2026-09-21T15:28:32.033Z'
exploitAvailable: true
---

## Overview

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application.

## Affected

- `smartermail < 100.0.9511`

## Remediation

Upgrade past the affected range:

- `smartermail 100.0.9511`
