Unknown · Ekia File Manager · CVE-2026-81301
**Name of the Vulnerable Software and Affected Versions**
Ekia File Manager version 1.2.7
**Description**
The application exposes `com.ekia.filecontrolmanager.OpenFileProvider` as an exported Android ContentProvider without requiring caller permissions. The provider maps a caller-controlled URI path directly to a filesystem path and passes it to the `new File(...)` function. It supports `query()`, `openFile()`, and `delete()` operations. Since the provider lacks `android:permission`, `android:readPermission`, or `android:writePermission`, a local application can access the provider authority to read, create, overwrite, or delete files accessible to the File Manager process.
**Recommendations**
Update Ekia File Manager to a version newer than 1.2.7.
As a temporary mitigation, restrict access to the `com.ekia.filecontrolmanager.OpenFileProvider` component.