SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-78196

MEDIUM · CVSS 4.4 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A path traversal vulnerability exists in the Android File Copy Routine within the achorein expo-share-intent component, specifically in the getDataColumn function. This flaw allows local attackers to manipulate the _display_name argument, potentially leading to unauthorized file access. Developers and organizations using affected versions up to 8.0.0 should prioritize upgrading to version 8.0.1 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-78196
Severity
MEDIUM
CVSS
4.4
EPSS
0.14%
Android

Original NVD Description

A security flaw has been discovered in achorein expo-share-intent up to 8.0.0. This affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component Android File Copy Routine. The manipulation of the argument _display_name results in path traversal. The attack requires a local approach. Upgrading to version 8.0.1 is able to mitigate this issue. The patch is identified as c6900b1ed06fcc3ca4b09651348974ac5b95e4e6. The affected component should be upgraded.