AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-49004

MEDIUM · CVSS 6.5 EPSS 0.69%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The built-in PostgreSQL service on Android devices is vulnerable due to misconfiguration and command injection flaws, allowing local attackers to exploit weak credentials and gain root access. This vulnerability poses a significant risk as it enables unauthorized users to bypass Android's permission sandbox. Android developers and device manufacturers should prioritize addressing this issue to protect user data and maintain system integrity.

CVE
CVE-2026-49004
Severity
MEDIUM
CVSS
6.5
EPSS
0.69%
Android

Original NVD Description

The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with root privileges, and is protected by weak credentials. The database supports the COPY FROM PROGRAM syntax, allowing local attackers to bypass Android's permission sandbox and gain full root access.