What is CVE-2026-47361?
In Datadog Android application versions prior to v541-5.9.2, BubbleChatActivity is exported without permission guard and accepts SEND intents with a caller-supplied conversation_id. This vulnerability allows an attacker to unconditionally cancel a notification when the activity closes without a matching in-process session.
Azərbaycanca: Datadog Android tətbiqinin v541-5.9.2-dən əvvəlki versiyalarında, BubbleChatActivity icazəsiz ixrac edilib və xarici SEND intent-ləri qəbul edir. Bu zəiflik təcavüzkara, uyğun gəlməyən conversation_id ilə bildirişi şərtsiz olaraq ləğv etməyə imkan verir.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: Datadog
FAQ2
Which versions of the Datadog Android application are affected by CVE-2026-47361?
This vulnerability affects versions of the Datadog Android application prior to v541-5.9.2.
What can an attacker achieve by exploiting CVE-2026-47361?
An attacker can unconditionally cancel a notification by sending an external SEND intent with a non-matching conversation_id.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.