CVE-2026-4218

A vulnerability was detected in myAEDES App up to 1.18.4 on Android. Affected is an unknown function of the file aedes/me/beta/utils/EngageBayUtils.java of the component aedes.me.beta. Performing a manipulation of the argument AUTH_KEY results in information disclosure. The attack is only possible with local access. The attack's complexity is rated as high. The exploitability is told to be difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

No configuration.

History

22 Apr 2026, 21:32

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad fue detectada en la aplicación myAEDES hasta la versión 1.18.4 en Android. Afecta a una función desconocida del archivo aedes/me/beta/utils/EngageBayUtils.java del componente aedes.me.beta. Realizar una manipulación del argumento AUTH_KEY resulta en revelación de información. El ataque solo es posible con acceso local. La complejidad del ataque se califica como alta. La explotabilidad se dice que es difícil. El exploit ahora es público y puede ser usado. El proveedor fue contactado tempranamente sobre esta revelación, pero no respondió de ninguna manera.

16 Mar 2026, 14:20

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 14:20

Updated : 2026-06-17 10:56


NVD link : CVE-2026-4218

Mitre link : CVE-2026-4218

CVE.ORG link : CVE-2026-4218


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-284

Improper Access Control