PT-2026-21499 · Unknown · Aliasvault Api

Nmaochea

·

Publicado

2026-02-23

·

Atualizado

2026-03-12

·

CVE-2026-2974

CVSS v3.1

2.5

Baixa

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions AliasVault App versions through 0.25.3
Description A security issue exists in AliasVault App on Android/iOS. The issue is related to the Backup Handler component and affects the shared prefs/aliasvault.xml file. Manipulation of the accessToken, refreshToken, metadata, key derivation params, and auth methods arguments can lead to unauthorized exposure of backup files. The attack requires local access and is considered complex and difficult to exploit. The tokens stored in aliasvault.xml are API session tokens and do not, on their own, allow decryption of the vault; the master password is still required.
Recommendations Upgrade to version 0.26.0 to resolve the issue.

Exploit

Correção

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-2974

Produtos afetados

Aliasvault Api