← Vulnerability feed

Vulnerability record · CVE-2025-48926 · published 28 May 2025

CVE-2025-48926: Smarsh telemessage authentication bypass via alternate path vulnerability

Smarsh · Telemessage

The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telephone numbers.

7.5 CVSS 3.1 High EPSS 0.25% · top 84.8% CWE-288 · Authentication bypass via alternate path
7.5CVSS 3.1 base score
0.25%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telephone numbers.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-48926 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.3CVE-2025-48927TeleMessage Spring Boot Actuator heap dump endpoint exposed by insecure defaultTeleMessage through 2025-05-05 ships with Spring Boot Actuator configured to expose the /heapdump endpoint. Because this is an insecure default initi…KEVEPSS 11%analysed4.0CVE-2025-48928TeleMessage TM SGNL JSP heap dump exposes passwords sent over HTTPThe TeleMessage service through 2025-05-05 runs a JSP application whose heap content is roughly equivalent to a core dump, and a password previously …KEVEPSS 0.55%analysed9.8CVE-2025-48929Smarsh telemessage insufficient session expiration vulnerabilityThe TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time)…EPSS 0.32%7.5CVE-2025-48925Smarsh telemessage vulnerabilityThe TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the auth…EPSS 0.26%7.5CVE-2025-47730Smarsh telemessage hard-coded credentials vulnerabilityThe TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app…EPSS 0.37%5.5CVE-2025-48931Smarsh telemessage vulnerabilityThe TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbow tables)…EPSS 0.09%5.3CVE-2025-48930Smarsh telemessage vulnerabilityThe TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to an adversa…EPSS 0.13%10.0CVE-2026-20079Cisco Secure Firewall Management Center authentication bypass to rootCisco Secure Firewall Management Center (FMC) Software contains an authentication bypass caused by an improper system process created at boot time. A…KEVEPSS 88%analysed

Source: NIST National Vulnerability Database (record CVE-2025-48926), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.