CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-94257: SMS Alert 3.9.6 to before 4.0.1

Affected technology

SMS Alert · 3.9.6 to before 4.0.1
Vendor not specified by the source

Description’s affected range: before 4.0.1 does not bind the account whose password is being changed to the phone number that was actually verified during its OTP password reset

Component: Not specified by the source

What an attacker can do

Unauthenticated attackers can set a new password on an arbitrary account, including an administrator, by verifying a one-time code sent to a phone number they control.

Published

KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-94257.html