Home

Description

WinMatrix agent developed by Simopro Technology has a Missing Authentication vulnerability, allowing authenticated local attackers to execute arbitrary code with SYSTEM privileges on the local machine as well as on all hosts within the environment where the agent is installed.

PUBLISHED Reserved 2026-04-15 | Published 2026-04-16 | Updated 2026-04-16 | Assigner twcert




CRITICAL: 9.3CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

HIGH: 8.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-306 Missing authentication for critical function

Product status

Default status
unaffected

3.5.13 (custom)
affected

References

www.twcert.org.tw/tw/cp-132-10839-2d9a7-1.html third-party-advisory

www.twcert.org.tw/en/cp-139-10840-ba9b9-2.html third-party-advisory

cve.org (CVE-2026-6348)

nvd.nist.gov (CVE-2026-6348)

Download JSON