What is CVE-2026-44965?
In Datadog Android application versions prior to v545-5.9.2, six App Widget configuration activities are exported without permission restrictions. This allows unauthorized local apps to access these widget configuration functions. Users should update to version v545-5.9.2 or later immediately.
Azərbaycanca: Datadog Android tətbiqinin v545-5.9.2-dən əvvəlki versiyalarında, altı ədəd App Widget konfiqurasiya aktivliyi (məsələn, IncidentWidgetActivity) heç bir icazə məhdudiyyəti olmadan ixrac edilib. Bu boşluq icazəsiz local proqramlara həmin widget konfiqurasiya funksiyalarına giriş imkanı yaradır. İstifadəçilər ən qısa zamanda v545-5.9.2 və ya daha yeni versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: Datadog
FAQ2
What type of applications can exploit the CVE-2026-44965 vulnerability in the Datadog Android app?
Unauthorized local apps can exploit this vulnerability to access the exported App Widget configuration functions.
What should Datadog Android users do to mitigate the CVE-2026-44965 vulnerability?
Users should update to version v545-5.9.2 or later immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.