CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-94256: SMS Alert 4.0.0 to before 4.0.1

Affected technology

SMS Alert · 4.0.0 to before 4.0.1
Vendor not specified by the source

Description’s affected range: before 4.0.1 does not verify that the account being logged in is the one the verified one-time code belongs to

Component: Not specified by the source

What an attacker can do

Unauthenticated attackers can sign in as any user with a stored phone number, including an administrator, by completing a code challenge on a phone they control.

Published

KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-94256.html