What is CVE-2026-44964?
In Datadog Android application versions prior to v545-5.9.2, the `OnCallNotificationActivity` is exported without permission guard. A malicious co-installed application can exploit this to launch the activity with attacker-controlled Intent extras, displaying arbitrary lock-screen messages or triggering fake on-call notifications. Users should immediately update to the latest version to mitigate this risk.
Azərbaycanca: Datadog Android tətbiqinin köhnə versiyalarında (v545-5.9.2-dən əvvəl) `OnCallNotificationActivity` komponenti icazə qoruyucusu olmadan ixrac edilib. Zərərli həm-quraşdırılmış tətbiq bu zəiflikdən istifadə edərək ixtiyari bildirişlər göstərə, ekranı kilidləyə və yanlış on-call səhifə məlumatları təqdim edə bilər. Tətbiqi dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: Datadog
FAQ2
In which component of the Datadog Android application was CVE-2026-44964 discovered?
The vulnerability was discovered in the `OnCallNotificationActivity` component, which was exported without a permission guard.
How can users protect themselves against CVE-2026-44964?
Users should immediately update the application to the latest version (v545-5.9.2 or higher).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.