CVE-2026-86443 MEDIUM

CVE-2026-86443: Cleartext Storage of Sensitive Information Vulnerability

Vendor Fermax Electronica S.a.u.
Product DuoxMe
Weakness CWE-312 · Cleartext storage
Published September 16, 2026
Last update September 16, 2026

CVSS base score

6.9/10
Attack vector Local
Attack complexity Low
Privileges required High
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N

What the vulnerability does

01Description

Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an attacker with local access to the device to retrieve the credentials stored by the application and impersonate the user account.

Key dates

02Disclosure timeline

September 16, 2026 CVE published
September 16, 2026 Record updated