SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18591

LOW · CVSS 2.1 EPSS 0.08% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

The Meesho Online Shopping App on Android is vulnerable due to improper handling of user input in the com.meesho.supply component, which can lead to the cleartext storage of sensitive information such as user IDs, phone numbers, email addresses, and names. This vulnerability can be exploited directly on the physical device, posing a risk to user privacy and data security. Android app developers and organizations using this application should prioritize addressing this issue to mitigate potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-18591
Severity
LOW
CVSS
2.1
EPSS
0.08%
Android

Original NVD Description

A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component com.meesho.supply. Such manipulation of the argument user_id/phone number/email address/name leads to cleartext storage of sensitive information. The attack can be executed directly on the physical device. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.