CVE-2026-6348 PUBLISHED

Simopro Technology|WinMatrix - Missing Authentication

Assigner: twcert
Reserved: 15.04.2026 Published: 16.04.2026 Updated: 16.04.2026

WinMatrix agent developed by Simopro Technology has a Missing Authentication vulnerability, allowing authenticated local attackers to execute arbitrary code with SYSTEM privileges on the local machine as well as on all hosts within the environment where the agent is installed.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.3

Product Status

Vendor Simopro Technology
Product WinMatrix
Versions Default: unaffected
  • affected from 3.5.13 to 3.5.26.15 (incl.)

Solutions

Update agent to version 3.5.27.5 or later.

References

Problem Types

  • CWE-306 Missing authentication for critical function CWE

Impacts

  • CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs