← Retour à la recherche de CVE

CVE-2026-49004

Description

The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with root privileges, and is protected by weak credentials. The database supports the COPY FROM PROGRAM syntax, allowing local attackers to bypass Android-s permission sandbox and gain full root access.

CVSS 6.5EPSS 0.6890000000000001%Risque 0.69
Voir la source
Publication
2026-08-05 07:16:37
Dernière modification
2026-08-05 15:16:52
Vecteur
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L