CVE-2026-4243Disclosure

LOWCVSS 1.1 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in La Nacion App 10.2.25 on Android. This impacts an unknown function of the file source/app/lanacion/clublanacion/BuildConfig.java of the component app.lanacion.activity. Executing a manipulation of the argument API_KEY_WEBSOCKET_CV can lead to unprotected storage of credentials. The attack can only be executed locally. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-255CWE-256

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-16: 2Technical Details · 2026-03-16: 103-16
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets3 URLs
Full discourse2 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4243 - La Nacion App app.lanacion.activity http://BuildConfig.java credentials storage Intel Report: https://ift.tt/GXSfEYW

    Post summary

    The note references CVE‑2026‑4243 with a brief mention of credential storage in the La Nacion app and a link to an intel report, but provides no technical depth or actionable details.

    0000040
    335 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4243 A weakness has been identified in La Nacion App 10.2.25 on Android. This impacts an unknown function of the file source/app/lanacion/clublanacion/BuildConfig.java of th… https://www.cve.org/CVERecord?id=CVE-2026-4243

    Post summary

    A weakness was reported in La Nacion App 10.2.25 on Android, affecting an unspecified function in BuildConfig.java, but no details on exploitation, patch, or active usage are provided.

    0000074
    56.7K followersView on X

Explore more