CVE-2026-22070

ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.
Configurations

Configuration 1 (hide)

cpe:2.3:a:oppo:coloros_assistant:1.4.26:*:*:*:*:*:*:*

History

05 May 2026, 02:53

Type Values Removed Values Added
CWE CWE-22
First Time Oppo coloros Assistant
Oppo
CPE cpe:2.3:a:oppo:coloros_assistant:1.4.26:*:*:*:*:*:*:*
References () https://security.oppo.com/en/noticeDetail?notice_only_key=NOTICE-2049764240746881024 - () https://security.oppo.com/en/noticeDetail?notice_only_key=NOTICE-2049764240746881024 - Vendor Advisory

30 Apr 2026, 15:48

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-30 09:16

Updated : 2026-05-05 02:53


NVD link : CVE-2026-22070

Mitre link : CVE-2026-22070

CVE.ORG link : CVE-2026-22070


JSON object : View

Products Affected

oppo

  • coloros_assistant
CWE
CWE-23

Relative Path Traversal

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')