{"id":"CVE-2026-94540","title":"DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's l…","summary":"DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's l…","severity":"high","cvss":7.7,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-306"],"vendor":"MrPear","product":"DesktopSMS","affected":["DesktopSMS <= 1.11.0"],"published":"2026-09-21","updated":"2026-09-22","sourceUpdated":"2026-09-22T20:53:07.383","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-94540","references":[{"url":"https://github.com/actuator/net.mrpear.apps.desktopsmslite","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/desktopsms-unauthorized-access-via-local-service","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"epss":0.00109,"epssPercentile":0.01387,"ingestedAt":"2026-09-21T22:54:37.970Z","slug":"CVE-2026-94540","body":"## Overview\n\nDesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can exploit the unauthenticated local service through same-device loopback to perform privileged SMS operations using the victim application's permissions.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":42.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}