CVE-2022-26629

CRITICAL

SoroushPlus+ Messenger <1.0.30 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-26629. PoCs published by scopion.

AI-analyzed exploit summary This PoC exploits an improper access control vulnerability (CVE-2022-26629) in SoroushPlus+ Messenger 1.0.30 by patching binary instructions to bypass the lock screen. It modifies specific offsets in the executable to disable authentication checks.

Description

An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function.

Exploits (1)

nomisec WORKING POC
by scopion · poc
https://github.com/scopion/CVE-2022-26629

This PoC exploits an improper access control vulnerability (CVE-2022-26629) in SoroushPlus+ Messenger 1.0.30 by patching binary instructions to bypass the lock screen. It modifies specific offsets in the executable to disable authentication checks.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: SoroushPlus+ Messenger 1.0.30
No auth needed
Prerequisites: Access to the target system · SoroushPlus+ installation directory · Python 3
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/sysenter-eip/CVE-2022-26629

Scores

CVSS v3 9.1
EPSS 0.3049
EPSS Percentile 96.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-863
Status published
Products (1)
splus/soroushplus 1.0.30
Published Mar 24, 2022
Tracked Since Feb 18, 2026