
CVE-2026-26228 VideoLAN VLC for Android prior to version 3.7.0 contains a path traversal vulnerability in the Remote Access Server routing for the authenticated endpoint GET /downlo… https://www.cve.org/CVERecord?id=CVE-2026-26228
Post summary
The CVE-2026-26228 vulnerability is a path traversal flaw in VLC for Android’s Remote Access Server, affecting versions prior to 3.7.0.

