CVE-2026-86701
Android application "ManabiPocket for Parents" contains an improper access control vulnerability in one of its components. A malicious appli
CVSS
2.5
Bajo
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 15 sept 2026 · Última mod.: 15 sept 2026 · CWE-926
Sin historial EPSS suficiente todavía.
Android application "ManabiPocket for Parents" contains an improper access control vulnerability in one of its components. A malicious application installed on the user's Android device may exploit the affected component via an Intent, potentially allowing the malicious application to obtain sensitive information from the affected application.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-81301——
———Ekia File Manager 1.2.7 exposes com.ekia.filecontrolmanager.OpenFileProvider as an exported Android ContentProvider without requiring caller permissions.
The provider maps the caller-controlled URI path directly to a filesystem path and passes it to new File(...). It then supports query(), openFile(), and delete() operations. Because the provider is exported and lacks android:permission, android:readPermission, or android:writePermission, another local application can access the provider authority and cause File Manager's process to read, create, overwrite, or delete files that are accessible to that process.15hCVE-2026-189947.1 ALT0.9%
——0A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files within the application.4dCVE-2026-21113—0.5%
——0Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission.5dCVE-2026-455287.3 ALT0.1%
——0In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.5dCVE-2026-205165.5 MED0.7%
——0In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11060069 / DTV04881615; Issue ID: MSV-7882.7dCVE-2026-21081—0.6%
——0Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.28d