CVE-2026-26214: CWE-297 Improper Validation of Certificate with Host Mismatch in Xiaomi Technology Co., Ltd. Galaxy FDS Android SDK
Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HTTPS is enabled (the default configuration). In GalaxyFDSClientImpl.createHttpClient(), the SDK configures Apache HttpClient with SSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER, which accepts any valid TLS certificate regardless of hostname mismatch. Because HTTPS is enabled by default in FDSClientConfiguration, all applications using the SDK with default settings are affected. This vulnerability allows a man-in-the-middle attacker to intercept and modify SDK communications to Xiaomi FDS cloud storage endpoints, potentially exposing authentication credentials, file contents, and API responses. The XiaoMi/galaxy-fds-sdk-android open source project has reached end-of-life status.
AI Analysis
Technical Summary
CVE-2026-26214 is a critical vulnerability in Xiaomi Technology Co., Ltd.'s Galaxy FDS Android SDK (version 3.0.8 and prior) where TLS hostname verification is disabled by default. The SDK configures Apache HttpClient with SSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER in the createHttpClient() method, which accepts any valid TLS certificate regardless of hostname mismatch. Because HTTPS is enabled by default, all applications using the SDK with default settings are vulnerable. This flaw allows a man-in-the-middle attacker to intercept and alter SDK communications to Xiaomi FDS cloud storage endpoints, risking exposure of authentication credentials, file contents, and API responses. The SDK is no longer maintained, and no patch or official fix is available.
Potential Impact
An attacker positioned to perform a man-in-the-middle attack can intercept and modify HTTPS communications between applications using the vulnerable Galaxy FDS Android SDK and Xiaomi FDS cloud storage endpoints. This can lead to exposure of sensitive data including authentication credentials, file contents, and API responses, compromising confidentiality and integrity of the data exchanged.
Mitigation Recommendations
The Galaxy FDS Android SDK is end-of-life and no official patch or fix is available. Users should discontinue use of this SDK and migrate to alternative, actively maintained solutions that properly validate TLS certificates including hostname verification. Until migration, avoid using the SDK with default HTTPS settings or implement additional application-level TLS validation if feasible.
CVE-2026-26214: CWE-297 Improper Validation of Certificate with Host Mismatch in Xiaomi Technology Co., Ltd. Galaxy FDS Android SDK
Description
Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HTTPS is enabled (the default configuration). In GalaxyFDSClientImpl.createHttpClient(), the SDK configures Apache HttpClient with SSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER, which accepts any valid TLS certificate regardless of hostname mismatch. Because HTTPS is enabled by default in FDSClientConfiguration, all applications using the SDK with default settings are affected. This vulnerability allows a man-in-the-middle attacker to intercept and modify SDK communications to Xiaomi FDS cloud storage endpoints, potentially exposing authentication credentials, file contents, and API responses. The XiaoMi/galaxy-fds-sdk-android open source project has reached end-of-life status.
CVSS v4.0
Score 9.1critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-26214 is a critical vulnerability in Xiaomi Technology Co., Ltd.'s Galaxy FDS Android SDK (version 3.0.8 and prior) where TLS hostname verification is disabled by default. The SDK configures Apache HttpClient with SSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER in the createHttpClient() method, which accepts any valid TLS certificate regardless of hostname mismatch. Because HTTPS is enabled by default, all applications using the SDK with default settings are vulnerable. This flaw allows a man-in-the-middle attacker to intercept and alter SDK communications to Xiaomi FDS cloud storage endpoints, risking exposure of authentication credentials, file contents, and API responses. The SDK is no longer maintained, and no patch or official fix is available.
Potential Impact
An attacker positioned to perform a man-in-the-middle attack can intercept and modify HTTPS communications between applications using the vulnerable Galaxy FDS Android SDK and Xiaomi FDS cloud storage endpoints. This can lead to exposure of sensitive data including authentication credentials, file contents, and API responses, compromising confidentiality and integrity of the data exchanged.
Mitigation Recommendations
The Galaxy FDS Android SDK is end-of-life and no official patch or fix is available. Users should discontinue use of this SDK and migrate to alternative, actively maintained solutions that properly validate TLS certificates including hostname verification. Until migration, avoid using the SDK with default HTTPS settings or implement additional application-level TLS validation if feasible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-02-11T20:08:07.943Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 698df2f6c9e1ff5ad8e60c1f
Added to database: 02/12/2026, 15:34:14 UTC
Last enriched: 07/15/2026, 11:08:02 UTC
Last updated: 09/10/2026, 19:36:53 UTC
Views: 300
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.