|
[Japanese]
|
JVNDB-2026-000145
|
Multiple vulnerabilities in Android application "Ticket Ryutsu Center"
|
Android application "Ticket Ryutsu Center" provided by Wavedash Co., Ltd. contains multiple vulnerabilities listed below:- Use of Hard-coded Credentials (CWE-798) - CVE-2026-92861
- Improper Authorization in Handler for Custom URL Scheme (CWE-939) - CVE-2026-92862
Koki Sato of BroadBand Security, Inc. reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V3 Severity: Base Metrics 4.0 (Medium) [IPA Score]
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: Low
- Integrity Impact: None
- Availability Impact: None
|
CVSS v4 Severity
Base Metrics: 5.1 (Medium) [IPA Score]
- Access Vector (AV): Local
- Attack Complexity (AC): Low
- Attack Requirements (AT): None
- Privileges Required (PR): None
- User Interaction (UI): None
Vulnerable System Impact
- Confidentiality Impact (VC): Low
- Integrity Impact (VI): None
- Availability Impact (VA): None
Subsequent System Impact
- Confidentiality Impact (SC): None
- Integrity Impact (SI): None
- Availability Impact (SA): None
The above CVSS base scores have been assigned for CVE-2026-92861
|
CVSS v3 Severity
Base Metrics: 3.3(Low) [IPA Score]
- Access Vector : Local
- Attack Complexity : Low
- Privileges Required : None
- User Interaction : Required
- Scope : Unchanged
- Confidentiality Impact : None
- Integrity Impact : Low
- Availability Impact : None
CVSS v4 Severity
Base Metrics: 4.6 (Medium) [IPA Score]
- Access Vector (AV): Local
- Attack Complexity (AC): Low
- Attack Requirements (AT): None
- Privileges Required (PR): None
- User Interaction (UI): Active
Vulnerable System Impact
- Confidentiality Impact (VC): None
- Integrity Impact (VI): Low
- Availability Impact (VA): None
Subsequent System Impact
- Confidentiality Impact (SC): None
- Integrity Impact (SI): None
- Availability Impact (SA): None
The above CVSS base scores have been assigned for CVE-2026-92862
|
|
Wavedash Co., Ltd.
- Android application "Ticket Ryutsu Center" 4.1.9 and earlier
|
|
- The hard-coded API key may be retrieved (CVE-2026-92861).
- When an intent is received from a malicious application, an attacker may lead a user to access an arbitrary website via the vulnerable application. As a result, the user may become a victim of a phishing attack (CVE-2026-92862).
|
[Update the Application]
Update the application to the latest version according to the information provided by the developer.
The developer has released the following version in October 2025 that contains a fix for this vulnerability. - Android application "Ticket Ryutsu Center" 4.2.0
The developer states that the affected versions require the users to update the application immediately when invoked.
Regarding CVE-2026-92861, the hard-code the API key has been deleted from the latest version.
Also the vulnerable API key has been deactivated, therefore the information contained in the vulnerable application cannot be abused.
|
Wavedash Co., Ltd.
|
- No Mapping(CWE-Other) [IPA Evaluation]
|
- CVE-2026-92861
- CVE-2026-92862
|
- JVN : JVN#53292492
|
- [2026/10/06]
Web page was published
|