CVE-2026-84431 - CERT CVE
ID CVE-2026-84431
Sažetak A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component com.airasia.mobile. Performing a manipulation of the argument _display_name results in path traversal. The attack requires a local approach. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Reference
CVSS
Base: 3.2
Impact: 4.9
Exploitability:3.1
Pristup
VektorSloženostAutentikacija
LOCAL LOW SINGLE
Impact
PovjerljivostCjelovitostDostupnost
NONE PARTIAL PARTIAL
CVSS vektor AV:L/AC:L/Au:S/C:N/I:P/A:P
Zadnje važnije ažuriranje 02-09-2026 - 02:17
Objavljeno 02-09-2026 - 02:17