CVSS7.8
Severityhigh
WeaknessNVD-CWE-Other
ExploitedNot in CISA KEV
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to trigger privileged functions.