CVE-2026-9222Disclosure

LOWCVSS 9.2 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-836

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-26: 3Technical Details · 2026-06-26: 306-26
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-9222 Authentication Bypass in Setracker2 Android App via Password Hash Exposure https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-9222

    Post summary

    The post announces an authentication bypass vulnerability (CVE‑2026‑9222) in the Setracker2 Android app caused by exposed password hashes, with no PoC, exploit code, or patch referenced.

    0000097
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-9222 Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client.… https://www.cve.org/CVERecord?id=CVE-2026-9222 ----- Traducción: CVE-2026-9222 Set… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑9222 with a short technical note and a link, but provides no PoC, exploit code, or mitigation information.

    0000034
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-9222 Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client.… https://www.cve.org/CVERecord?id=CVE-2026-9222

    Post summary

    The post discloses CVE-2026-9222 for the Setracker2 Android Companion App, noting that older versions need only a password hash for backend authentication, but provides no PoC, exploit, patch, or active exploitation details.

    00000748
    57.7K followersView on X

Explore more