PT-2026-29993 · Unknown+1 · Noelse Individuals & Pro App+1
Fxizenta
·
Published
2026-04-03
·
Updated
2026-04-03
·
CVE-2026-5458
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Noelse Individuals & Pro App versions through 2.1.7
Description
A weakness exists in Noelse Individuals & Pro App on Android, up to version 2.1.7. The issue involves manipulation of the
SEGMENT WRITE KEY argument within an unknown function of the file com/reactnative/antelop/BuildConfig.java of the com.afone.noelse component, leading to the use of a hard-coded cryptographic key. The attack requires local access. The exploit has been publicly released.Recommendations
Update Noelse Individuals & Pro App to a version later than 2.1.7.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android
Noelse Individuals & Pro App