[Japanese]

JVNDB-2026-000145

Multiple vulnerabilities in Android application "Ticket Ryutsu Center"

Overview

Android application "Ticket Ryutsu Center" provided by Wavedash Co., Ltd. contains multiple vulnerabilities listed below:
  • Use of Hard-coded Credentials (CWE-798) - CVE-2026-92861
  • Improper Authorization in Handler for Custom URL Scheme (CWE-939) - CVE-2026-92862
Koki Sato of BroadBand Security, Inc. reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 4.0 (Medium) [IPA Score]
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: Low
  • Integrity Impact: None
  • Availability Impact: None
CVSS v4 Severity
Base Metrics: 5.1 (Medium) [IPA Score]
  • Access Vector (AV): Local
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): None
  • Privileges Required (PR): None
  • User Interaction (UI): None
  • Vulnerable System Impact
  • Confidentiality Impact (VC): Low
  • Integrity Impact (VI): None
  • Availability Impact (VA): None
  • Subsequent System Impact
  • Confidentiality Impact (SC): None
  • Integrity Impact (SI): None
  • Availability Impact (SA): None
The above CVSS base scores have been assigned for CVE-2026-92861


CVSS v3 Severity
Base Metrics: 3.3(Low) [IPA Score]
  • Access Vector : Local
  • Attack Complexity : Low
  • Privileges Required : None
  • User Interaction : Required
  • Scope : Unchanged
  • Confidentiality Impact : None
  • Integrity Impact : Low
  • Availability Impact : None
CVSS v4 Severity
Base Metrics: 4.6 (Medium) [IPA Score]
  • Access Vector (AV): Local
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): None
  • Privileges Required (PR): None
  • User Interaction (UI): Active
  • Vulnerable System Impact
  • Confidentiality Impact (VC): None
  • Integrity Impact (VI): Low
  • Availability Impact (VA): None
  • Subsequent System Impact
  • Confidentiality Impact (SC): None
  • Integrity Impact (SI): None
  • Availability Impact (SA): None
The above CVSS base scores have been assigned for CVE-2026-92862
Affected Products


Wavedash Co., Ltd.
  • Android application "Ticket Ryutsu Center" 4.1.9 and earlier

Impact

  • The hard-coded API key may be retrieved (CVE-2026-92861).
  • When an intent is received from a malicious application, an attacker may lead a user to access an arbitrary website via the vulnerable application. As a result, the user may become a victim of a phishing attack (CVE-2026-92862).
Solution

[Update the Application]
Update the application to the latest version according to the information provided by the developer.
The developer has released the following version in October 2025 that contains a fix for this vulnerability.
  • Android application "Ticket Ryutsu Center" 4.2.0
The developer states that the affected versions require the users to update the application immediately when invoked.
Regarding CVE-2026-92861, the hard-code the API key has been deleted from the latest version.
Also the vulnerable API key has been deactivated, therefore the information contained in the vulnerable application cannot be abused.
Vendor Information

Wavedash Co., Ltd.
CWE (What is CWE?)

  1. No Mapping(CWE-Other) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2026-92861
  2. CVE-2026-92862
References

  1. JVN : JVN#53292492
Revision History

  • [2026/10/06]
      Web page was published