← Back to search

CVE-2026-94540

7.7 HIGHpublic exploit available

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
DesktopSMS 1.11.0 allows local attackers to transmit and retrieve SMS content without user interaction due to an unauthorized access vulnerability.
Exploitability
Exploitation is relatively easy as it requires only local access to the application's unauthenticated service.
Blast radius
If exploited, this could lead to unauthorized control over SMS operations on the victim’s device, potentially compromising sensitive information.
Prioritized remediation
Update DesktopSMS to the latest version or apply vendor-provided patches immediately.
auth-bypasssmslocal-attackprivilege-elevation

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can exploit the unauthenticated local service through same-device loopback to perform privileged SMS operations using the victim application's permissions.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-306

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.