PT-2026-91252 · Unknown · Ekia File Manager
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Ekia File Manager version 1.2.7
Description
The application exposes
com.ekia.filecontrolmanager.OpenFileProvider as an exported Android ContentProvider without requiring caller permissions. The provider maps a caller-controlled URI path directly to a filesystem path and passes it to the new File(...) function. It supports query(), openFile(), and delete() operations. Since the provider lacks android:permission, android:readPermission, or android:writePermission, a local application can access the provider authority to read, create, overwrite, or delete files accessible to the File Manager process.Recommendations
Update Ekia File Manager to a version newer than 1.2.7.
As a temporary mitigation, restrict access to the
com.ekia.filecontrolmanager.OpenFileProvider component.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ekia File Manager