PT-2026-22155 · Videolan · Vlc For Android

Stanislav Fort

·

Published

2026-02-26

·

Updated

2026-02-26

·

CVE-2026-26228

CVSS v3.1

4.9

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions VideoLAN VLC for Android versions prior to 3.7.0
Description The software contains a path traversal issue in the Remote Access Server routing for the authenticated endpoint ''/download''. The file query parameter is combined into a filesystem path without proper validation, potentially allowing a network-based attacker to request files outside the intended directory. The impact is limited by Android’s security features, typically restricting access to app-internal and app-specific external storage.
Recommendations Update VideoLAN VLC for Android to version 3.7.0 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-26228

Affected Products

Vlc For Android