PT-2026-22155 · Videolan · Vlc For Android

Stanislav Fort

·

Publicado

2026-02-26

·

Atualizado

2026-02-26

·

CVE-2026-26228

CVSS v3.1

4.9

Média

VetorAV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions VideoLAN VLC for Android versions prior to 3.7.0
Description The software contains a path traversal issue in the Remote Access Server routing for the authenticated endpoint ''/download''. The file query parameter is combined into a filesystem path without proper validation, potentially allowing a network-based attacker to request files outside the intended directory. The impact is limited by Android’s security features, typically restricting access to app-internal and app-specific external storage.
Recommendations Update VideoLAN VLC for Android to version 3.7.0 or later.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-26228

Produtos afetados

Vlc For Android