PT-2026-31464 · Abrignoni+1 · Valeapp

CVE-2026-40027

·

Published

2026-04-08

·

Updated

2026-04-08

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ALEAPP (Android Logs Events And Protobuf Parser) versions prior to 3.4.1
Description The NQ Vault.py artifact parser contains a path traversal flaw. This occurs because the parser uses the file name from variable, which is controlled by an attacker via a database, directly as the output filename. This allows arbitrary file writes outside the designated report output directory. By embedding a path traversal payload, such as ../../../outside written.bin, an attacker can write files to arbitrary locations, which may lead to code execution by overwriting configuration or executable files.
Recommendations Update ALEAPP (Android Logs Events And Protobuf Parser) to version 3.4.1 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40027

Affected Products

Valeapp