LIVE · cybersecurity feed
Live wire
cve recordlow

CVE-2026-4243

Published
CVSS2.5
Severitylow
WeaknessCWE-255
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

A weakness has been identified in La Nacion App 10.2.25 on Android. This impacts an unknown function of the file source/app/lanacion/clublanacion/BuildConfig.java of the component app.lanacion.activity. Executing a manipulation of the argument API_KEY_WEBSOCKET_CV can lead to unprotected storage of credentials. The attack can only be executed locally. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-4243

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-4243.