Authentication bypass using an alternate path or channel in KACE Systems Management Appliance (SMA) - CVE-2025-32976
Published: April 24, 2026
KACE Systems Management Appliance (SMA)
Detailed vulnerability description
The vulnerability allows a remote user to bypass TOTP-based two-factor authentication.
The vulnerability exists due to authentication bypass using an alternate path in the 2FA validation process when validating two-factor authentication. A remote user can exploit a logic flaw to bypass TOTP-based two-factor authentication.
The issue affects the two-factor authentication implementation.