What is CVE-2026-47363?
CVE-2026-47363 is a vulnerability in older versions of the Datadog Android app (prior to v541-5.9.2) where the exported launcher `AppActivity` accepts an attacker-supplied session (including OAuth tokens) from `Intent extras` without validation. This allows forcing the app into a malicious session without backend verification. Updating to v541-5.9.2 or later is recommended.
Azərbaycanca: CVE-2026-47363 Datadog Android tətbiqinin köhnə versiyalarında (`v541-5.9.2`-dən əvvəl) launcher `AppActivity`-nin ixrac edilməsi zəifliyidir. Təcavüzkar `Intent extras` vasitəsilə zərərli sessiya (OAuth tokenləri daxil) təqdim edərək tətbiqi arxa plan doğrulaması olmadan həmin sessiyaya daxil edə bilər. Tətbiqi `v541-5.9.2` və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which versions of the Datadog Android app are affected by CVE-2026-47363?
All versions prior to v541-5.9.2 are affected.
What action is recommended to mitigate CVE-2026-47363?
Updating the app to v541-5.9.2 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.