Skip to main content

Threats Tagged 'cwe-926'

View all threats tagged with 'cwe-926'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-926

Threats Tagged 'cwe-926'

Click on any threat for detailed analysis and mitigation recommendations

Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins/terminal/src/android/TerminalService.java does not verify the caller. Any installed Android application can bind the service and send MSG_EXEC with an attacker-controlled cmd value, which the terminal implementation passes to ProcessBuilder with sh -c inside Acode's UID. This allows a zero-permission local application to execute commands with access to Acode private data, remote credentials, Storage Access Framework grants, and runtime permissions without additional interaction at attack time. This issue is fixed in version 1.12.7.

Join the discussion

Ekia File Manager 1.2.7 exposes com.ekia.filecontrolmanager.OpenFileProvider as an exported Android ContentProvider without requiring caller permissions. The provider maps the caller-controlled URI path directly to a filesystem path and passes it to new File(...). It then supports query(), openFile(), and delete() operations. Because the provider is exported and lacks android:permission, android:readPermission, or android:writePermission, another local application can access the provider authority and cause File Manager's process to read, create, overwrite, or delete files that are accessible to that process.

Join the discussion

CVE-2026-18994 is a high-severity vulnerability in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market. It involves improper authorization due to improper export of application components, allowing a local authenticated user to read or modify protected files within the app. The affected versions are all versions prior to 9.8.1.77. There is no information about an available patch or official fix at this time.

Join the discussion

An improper export of Android application components in Visual Voicemail versions prior to 20.1.00.05 allows local attackers to initiate calls without proper permission. This vulnerability is identified as CVE-2026-21113 and has a medium severity rating with a CVSS score of 5.5.

Join the discussion

CVE-2026-21108 is a vulnerability in Bixby Touch Android application versions prior to 4.3.01.17. It involves improper export of application components that allows local attackers to access sensitive information. The vulnerability has a medium severity with a CVSS score of 5.5. The issue is fixed starting from version 4.3.01.17.

Join the discussion

In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11060069 / DTV04881615; Issue ID: MSV-7882.

Join the discussion

CVE-2026-21081 is a medium severity vulnerability in SamsungPassAutofill prior to version 5.2.10. It involves improper export of Android application components, which allows local attackers to access sensitive information. Exploitation requires user interaction. No official patch or remediation guidance is currently confirmed.

Join the discussion

CVE-2026-21063 is a medium severity vulnerability in Samsung Mobile Devices related to improper export of Android application components in the AppLock feature prior to the SMR Aug-2026 Release 1. This flaw allows physical attackers to bypass the app lock function, potentially exposing locked applications. The vulnerability is identified as CWE-926, indicating improper export of components. No specific affected versions are provided, and no official patch or remediation guidance is currently available.

Join the discussion

CVE-2026-21059 is a medium severity vulnerability affecting Samsung Contacts on Samsung Mobile Devices prior to the SMR Aug-2026 Release 1. It involves improper export of Android application components, which allows local attackers to delete files with the privileges of the Samsung Contacts app.

Join the discussion

In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, MonitorSavedViewWidgetActivity, OnCallShiftsWidgetActivity, OnCallPagesWidgetActivity, SloWidgetActivity, DashboardWidgetActivity) are exported with no permission guard. Each accepts a caller-supplied AppWidgetManager.EXTRA_APPWIDGET_ID and, when no deep-link destination is resolved, uses it to load the matching widget's stored session and automatically log in as that user. Because Android widget IDs are small sequential integers, a co-installed application can brute-force this value to find one that matches a widget configured on the victim's device. This requires: A malicious application co-installed on the victim's device. At least one of the six widgets configured on the victim's home screen. An active Datadog session cached locally. Impact: The matching configuration activity opens in the foreground under the victim's session and renders live infrastructure data. Exposure is limited to a visual side channel (e.g., screen recording or accessibility services); the calling application cannot programmatically read the rendered data.

Join the discussion

Showing 1 to 10 of 41 results

Filters:Tag: cwe-926
Page 1 of 5
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses