MEDIUM

CVE-2026-86443

2026-09-16 CVSS v4.0
CVSS
6.9

Description

Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an attacker with local access to the device to retrieve the credentials stored by the application and impersonate the user account.

Weakness (CWE)

CWE-312

EPSS Score

0.1%
Probability of exploitation in next 30 days
0.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE