CVE-2026-12190
Essential information
- Published
- 15/06/2026 01:16
- Modified
- 15/06/2026 20:42
- Author
- The MITRE Corporation
- Creator
- The MITRE Corporation
- CVSS
- 4.3 (v2) 5.3 MEDIUM (v3.1) 4.8 MEDIUM (v4.0)
- CISA KEV
- No
- CWE
- CWE-285
- CVSS vector
-
AV:L/AC:L/Au:S/C:P/I:P/A:PCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS metrics
- Access vector
- Local
- Access complexity
- Low
- Authentication
- Single
- Confidentiality impact
- Partial
- Integrity impact
- Partial
- Availability impact
- Partial
- Exploitability
- —
- Remediation level
- —
- Report confidence
- —
- Temporal score
- —
- Attack vector
- Local
- Attack complexity
- Low
- Privileges required
- Low
- User interaction
- None
- Scope
- Unchanged
- Confidentiality impact
- Low
- Integrity impact
- Low
- Availability impact
- Low
- Exploit code maturity
- —
- Remediation level
- —
- Report confidence
- —
- Temporal score
- —
- Attack vector
- Local
- Attack complexity
- Low
- Attack requirements
- None
- Privileges required
- Low
- User interaction
- None
- Confidentiality (V)
- Low
- Confidentiality (S)
- None
- Integrity (V)
- Low
- Integrity (S)
- None
- Availability (V)
- Low
- Availability (S)
- None
- Exploit maturity
- NOT_DEFINED
Description
A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability affects unknown code of the component ai.mainfunc.genspark. The manipulation leads to improper authorization in handler for custom url scheme. The attack can only be performed from a local environment. The vendor was contacted early about this disclosure but did not respond in any way.
NVD status
- Status
- Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
- Source
- [email protected]
- NVD
- View on NVD
Affected products (CPE)
| Product | CPE |
|---|---|
| genspark / ai workspace app | cpe:2.3:a:genspark:ai_workspace_app:2.8.4:*:*:*:*:*:*:* |