Executive brief
SmarterMail is a popular enterprise-grade email and collaboration server. A critical security flaw allows unauthenticated attackers to remotely execute commands on the server by redirecting the application to a malicious external source. This could lead to a total compromise of the email server, including the theft of sensitive communications, loss of service, and a foothold for further attacks on the corporate network.
Technical details
A missing authentication vulnerability (CWE-306) exists in the ConnectToHub API method within SmarterTools SmarterMail. An unauthenticated remote attacker can exploit this by sending a crafted request that points the SmarterMail instance to a malicious HTTP server. The application then fetches and executes OS commands provided by the attacker's server. This vulnerability is being exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The issue is resolved in SmarterMail build 9511.
Affected products
- SmarterTools SmarterMail Prior to build 9511
Timeline
- 2026-01-23: disclosed: Initial publication by VulnCheck
- 2026-02-05: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2026-02-05: advisory: NVD advisory published/updated