Junglewise Threat Intelligence

CVE-2026-6348: Simopro Technology WinMatrix agent missing authentication

CVE-2026-6348 · Severity: high · CVSS 8.8 · Published 2026-04-16

Executive brief

The WinMatrix agent, a management tool used for monitoring and controlling computers within an organization, contains a security flaw that allows a user already logged into a computer to gain full administrative control. An attacker could use this to run unauthorized software with the highest possible system privileges, potentially spreading the attack to every other computer in the network where the agent is installed. This could lead to a total compromise of the organization's IT infrastructure and data.

Technical details

A Missing Authentication vulnerability (CWE-306) exists in the WinMatrix agent developed by Simopro Technology. The flaw allows an authenticated local attacker with low privileges to bypass security checks and execute arbitrary code with SYSTEM-level authority. Because the agent is designed for environment-wide management, the vulnerability can be leveraged to execute code on all other hosts within the network that have the agent installed. The issue affects versions 3.5.13 through 3.5.26.15 and has been addressed in version 3.5.27.5.

Affected products

  • Simopro Technology WinMatrix agent 3.5.13 to 3.5.26.15

Timeline

  • 2026-04-16: disclosed
  • 2026-04-16: advisory
  • 2026-04-16: patched: Fixed in version 3.5.27.5

References