References https://zhuanlan.zhihu.com/p/1997751124111942608 https://developer.cloud.tencent.com/article/2631609 https://www.secrss.com/articles/87398 https://cn-sec.com/archives/4951131.html https://www.cyfirma.com/research/cve-2026-23760-smartertools-smartermail-authentication-bypass-vulnerability/ https://labs.watchtowr.com/attackers-with-decompilers-strike-again-smartertools-smartermail-wt-2026-0001-auth-bypass/ https://www.cve.org/CVERecord?id=CVE-2026-23760 https://portal.smartertools.com/community/a97695/critical-sm-build-9511-unauthenticated-admin-account-takeover-possible.aspx https://nvd.nist.gov/vuln/detail/CVE-2026-24423 https://www.vulncheck.com/advisories/smartertools-smartermail-unauthenticated-rce-via-connecttohub-api
Related VulnerabilitiesPoCCVE-2026-24423: SmarterMail - Remote Code ExecutionPoCSmarterMail ConnectToHub /api/v1/settings/sysadmin/connect-to-hub 命令执行漏洞(CVE-2026-24423)SmarterTools SmarterMail 远程代码执行漏洞(CVE-2026-24423)PoCCVE-2026-23760: SmarterTools SmarterMail - Admin Password ResetPoCSmarterMail /api/v1/auth/force-reset-password 权限绕过漏洞SmarterMail 存在任意文件上传漏洞SmarterMail 存在任意密码重置漏洞Smartertools Smartermail 未授权 文件上传限制不当漏洞PoCCVE-2025-52691: SmarterMail - Unrestricted File UploadPoCCVE-2022-24384: SmarterTools SmarterTrack - Cross-Site Scripting