PT-2026-96311 · Unknown · Desktopsms

·

CVE-2026-94540

·

Published

2026-09-21

·

Updated

2026-09-22

CVSS v3.1

7.7

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions DesktopSMS version 1.11.0
Description An unauthorized access issue exists in the application's local service. Local attackers can interact with this unauthenticated service via same-device loopback to perform privileged SMS operations using the application's permissions. This allows for the transmission of SMS, retrieval of SMS-derived content, and the persistence of an attacker-selected paired identity without requiring user interaction or pairing confirmation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94540

Affected Products

Desktopsms