OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-94540

HIGH · CVSS 7.7 EPSS 0.16% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

DesktopSMS 1.11.0 contains a vulnerability that allows local attackers to exploit the application's service to send and retrieve SMS messages without user interaction or pairing confirmation. This unauthorized access can lead to the compromise of sensitive SMS-derived content and the establishment of a persistent attacker-controlled identity. Organizations using this application should prioritize remediation to prevent potential data breaches and unauthorized communications.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-94540
Severity
HIGH
CVSS
7.7
EPSS
0.16%

Original NVD Description

DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can exploit the unauthenticated local service through same-device loopback to perform privileged SMS operations using the victim application's permissions.