CVE-2025-48926
Published May 28, 2025
·Updated
The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telephone numbers.
Affected Software
2 affected components
TeleMessage TeleMessage service<=2025-05-05
Smarsh TeleMessage<=2025-05-05
Event History
May 28, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48926?
CVE-2025-48926 is considered a critical vulnerability as it exposes sensitive user information in the TeleMessage service.
2
How do I fix CVE-2025-48926?
To fix CVE-2025-48926, ensure that you update the TeleMessage service to a version released after May 5, 2025.
3
What types of data are exposed in CVE-2025-48926?
CVE-2025-48926 exposes usernames, e-mail addresses, passwords, and telephone numbers of users.
4
Is CVE-2025-48926 being actively exploited?
Yes, CVE-2025-48926 has been reported to be actively exploited in the wild as of May 2025.
5
Which versions of TeleMessage are affected by CVE-2025-48926?
CVE-2025-48926 affects all versions of the TeleMessage service up to and including version released on May 5, 2025.