CVE-2026-44964: CWE-441 Unintended Proxy or Intermediary ('Confused Deputy') in Datadog Android App
In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with no permission guard. A co-installed application can launch it with attacker-controlled Intent extras, including a full-screen lock-screen message, an arbitrary on-call page ID, and an arbitrary Intent to run inside the Datadog process. This requires: A malicious application co-installed on the victim's device. An active Datadog session in the Android app. Impact: After a single tap on the Acknowledge button, the app sends a forged on-call acknowledgement to the backend under the victim's session, launches the attacker-supplied Intent from within the Datadog process (reaching otherwise non-exported components), and turns on the screen while dismissing the keyguard.
AI Analysis
Technical Summary
The Datadog Android app (version 5.9.2) contains a CWE-441 Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in the OnCallNotificationActivity, which is declared android:exported="true" without permission guards. A malicious co-installed app can launch this activity with attacker-controlled Intent extras, causing three main effects after a user tap: (1) a forged Acknowledge request is sent to the Datadog backend using the victim's authenticated session and attacker-chosen page_id; (2) the attacker-controlled Intent is launched from within the Datadog process, enabling access to non-exported components; (3) the device keyguard is dismissed and the screen is turned on, potentially facilitating social engineering or annoyance. This requires a malicious app on the device and an active Datadog session. No CVSS score or vendor remediation information is currently available.
Potential Impact
An attacker with a malicious app on the same device can abuse the exported OnCallNotificationActivity to send unauthorized Acknowledge requests to the Datadog backend using the victim's authenticated session, potentially manipulating on-call notifications. The attacker can also launch arbitrary Intents within the Datadog app context, gaining access to non-exported components, and dismiss the device keyguard while turning on the screen, which may be used for social engineering or user annoyance. This compromises the integrity of on-call notification acknowledgments and may affect user trust and device security.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid installing untrusted applications alongside the Datadog Android app and consider restricting app permissions where possible to limit co-installed app capabilities. Monitor official Datadog channels for updates regarding a fix or mitigation.
CVE-2026-44964: CWE-441 Unintended Proxy or Intermediary ('Confused Deputy') in Datadog Android App
Description
In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with no permission guard. A co-installed application can launch it with attacker-controlled Intent extras, including a full-screen lock-screen message, an arbitrary on-call page ID, and an arbitrary Intent to run inside the Datadog process. This requires: A malicious application co-installed on the victim's device. An active Datadog session in the Android app. Impact: After a single tap on the Acknowledge button, the app sends a forged on-call acknowledgement to the backend under the victim's session, launches the attacker-supplied Intent from within the Datadog process (reaching otherwise non-exported components), and turns on the screen while dismissing the keyguard.
CVSS v3.1
Score 6.5medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Datadog Android app (version 5.9.2) contains a CWE-441 Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in the OnCallNotificationActivity, which is declared android:exported="true" without permission guards. A malicious co-installed app can launch this activity with attacker-controlled Intent extras, causing three main effects after a user tap: (1) a forged Acknowledge request is sent to the Datadog backend using the victim's authenticated session and attacker-chosen page_id; (2) the attacker-controlled Intent is launched from within the Datadog process, enabling access to non-exported components; (3) the device keyguard is dismissed and the screen is turned on, potentially facilitating social engineering or annoyance. This requires a malicious app on the device and an active Datadog session. No CVSS score or vendor remediation information is currently available.
Potential Impact
An attacker with a malicious app on the same device can abuse the exported OnCallNotificationActivity to send unauthorized Acknowledge requests to the Datadog backend using the victim's authenticated session, potentially manipulating on-call notifications. The attacker can also launch arbitrary Intents within the Datadog app context, gaining access to non-exported components, and dismiss the device keyguard while turning on the screen, which may be used for social engineering or user annoyance. This compromises the integrity of on-call notification acknowledgments and may affect user trust and device security.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid installing untrusted applications alongside the Datadog Android app and consider restricting app permissions where possible to limit co-installed app capabilities. Monitor official Datadog channels for updates regarding a fix or mitigation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- hackerone
- Date Reserved
- 2026-05-08T15:00:02.447Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a762368bf8831d539ed4415
Added to database: 08/07/2026, 18:26:48 UTC
Last enriched: 08/07/2026, 18:46:45 UTC
Last updated: 08/08/2026, 01:44:07 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.