Sceawere

Vulnerability Detail

CVE-2026-76757UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Drupal Gammu SMS Daemon Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.9
Creation Date
20h ago
Vendor
Drupal
Product
Gammu SMS Daemon
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.9",
  "pubDate": "2026-09-02T13:18:10.977Z",
  "pubdate": "2026-09-02T13:18:10.977Z",
  "executiveSummary": "The Gammu SMS Daemon module for Drupal is subject to an unspecified vulnerability affecting all versions of the software. This vulnerability represents a potential security risk to the integrity and availability of the SMS gateway integration within a Drupal environment.\nThe nature of the vulnerability suggests a failure in input sanitization or insecure handling of SMS-related command structures. If exploited, an unauthorized actor could potentially trigger unintended actions within the daemon or the underlying system, leading to unauthorized message dispatch, information disclosure, or service disruption.\nThe vulnerability affects all Drupal instances currently utilizing the Gammu SMS Daemon module. Because the SMS daemon often operates with elevated system-level permissions to interact with hardware or external gateway APIs, successful exploitation may allow an attacker to bypass standard application-level controls.\nRisk implications are significant, as vulnerabilities in communication daemons can be leveraged for command injection, spoofing, or denial-of-service against the messaging infrastructure. Attackers typically require network access to the target system or the ability to influence the input processed by the Gammu daemon to execute an exploit. Given the broad version scope, immediate assessment of the module's implementation within the specific Drupal environment is required to determine the actual attack surface.",
  "technicalDetails": "The vulnerability resides within the architecture of the Gammu SMS Daemon module for Drupal, which acts as a bridge between the Drupal content management system and the Gammu SMSD service. The core issue pertains to how the module processes data streams or user-supplied input before passing them to the Gammu backend for message dispatch or status reporting.\nIn a standard implementation, the module interacts with the Gammu SMSD backend via local pipes, database tables, or the Gammu SMSD service interface. The vulnerability likely stems from insufficient validation of parameters passed to the Gammu execution layer. When user-controlled input, such as SMS recipient identifiers, message content, or configuration parameters, is improperly sanitized, it may lead to shell command injection or manipulation of the Gammu SMSD configuration files.\nThe attack flow typically follows a trajectory where an attacker identifies an input vector within the Drupal module interface—such as an SMS notification trigger or a settings configuration form—that is subsequently processed by the daemon. By injecting malicious metadata or specifically crafted payloads into these fields, an attacker can influence the execution context of the Gammu service. If the underlying system invokes the daemon with elevated privileges, the payload may execute with the permissions of the web server or the dedicated service user, facilitating arbitrary command execution on the host operating system.\nFurthermore, if the vulnerability allows for the direct manipulation of the Gammu configuration—which often resides in local files—an attacker could theoretically modify the SMSD parameters to redirect message traffic, disable logging mechanisms to mask malicious activity, or point the daemon to a malicious gateway server. This facilitates exfiltration of SMS traffic or man-in-the-middle attacks on the messaging flow.\nThe vulnerable component involves the integration logic responsible for relaying Drupal events to the external SMS system. Because this affects all versions of the Gammu SMS Daemon module, the vulnerability appears to be architectural rather than a regression in a specific release. Authentication requirements depend on the exposure of the triggering endpoint; however, if the SMS trigger is exposed via publicly accessible Drupal forms or API endpoints, no prior authentication may be required for a remote actor to initiate the exploit sequence.\nPost-exploitation, an attacker can gain persistent access to the messaging gateway, allowing for the interception of two-factor authentication tokens or sensitive information transmitted via SMS, significantly compromising the security posture of the Drupal installation and its integrated communication services."
}
CVE-2026-76757: Drupal Gammu SMS Daemon Vulnerability (MEDIUM Severity, CVSS: 5.9) - Sceawere