Known vulnerability record

CVE-2026-24423

SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability

Stable IDcve:CVE-2026-24423Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability

SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a malicious HTTP server which serves the malicious OS command and could lead to command execution.

Keep the signals separate

CVSS severitycriticalScore 9.3 · source VulnCheck
EPSS probability87.7%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-02-05
Ransomware useknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2026-01-23
CVE modified
2026-08-04
KEV date added
2026-02-05
Dataset fetched
2026-08-21T03:55:01.783Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.