PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application… (CVE-2026-13462)
PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application webviews. A remote and unauthenticated attacker can steal information that the user sends.
AI Analysis
Technical Summary
CVE-2026-13462 describes an SSL bypass vulnerability in the PayRange Android app versions 7.0.7 and below. The vulnerability allows invalid SSL certificates to be accepted within application webviews, which can be exploited remotely without authentication. This enables attackers to capture sensitive information transmitted by users through the app. The CVSS 3.1 vector indicates a network attack vector with low attack complexity, no privileges or user interaction required, and a high impact on confidentiality only.
Potential Impact
An attacker can remotely intercept and steal sensitive information sent by users through the vulnerable app due to acceptance of invalid SSL certificates. This compromises the confidentiality of user data but does not affect integrity or availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid transmitting sensitive information via the affected app versions. Monitor for vendor updates regarding patches or mitigations.
PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application… (CVE-2026-13462)
Description
PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application webviews. A remote and unauthenticated attacker can steal information that the user sends.
CVSS v3.1
Score 7.5high
Affected software
pkg:github/payrange/PayRange-AndroidRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-13462 describes an SSL bypass vulnerability in the PayRange Android app versions 7.0.7 and below. The vulnerability allows invalid SSL certificates to be accepted within application webviews, which can be exploited remotely without authentication. This enables attackers to capture sensitive information transmitted by users through the app. The CVSS 3.1 vector indicates a network attack vector with low attack complexity, no privileges or user interaction required, and a high impact on confidentiality only.
Potential Impact
An attacker can remotely intercept and steal sensitive information sent by users through the vulnerable app due to acceptance of invalid SSL certificates. This compromises the confidentiality of user data but does not affect integrity or availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid transmitting sensitive information via the affected app versions. Monitor for vendor updates regarding patches or mitigations.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-wpmg-2gv8-722g
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-13462"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a50ba6868715ace4357f663
Added to database: 07/10/2026, 09:24:56 UTC
Last enriched: 07/10/2026, 09:47:14 UTC
Last updated: 07/31/2026, 19:22:57 UTC
Views: 42
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.