Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-26230

20
FAUCET Score

CVE-2020-26230 allowed for the identification and de-anonymization of COVID-19 positive users of Spain's Radar COVID exposure notification app. The vulnerability stemmed from the fact that only positive users' apps connected to the backend server, enabling on-path observers (like ISPs or MNOs) to identify infected individuals. With a CVSS score of 5.3 (Medium), the attack required high complexity and user interaction to achieve high confidentiality impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability, which has since been mitigated by injecting dummy traffic from all users.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.1.2CPE matchmatch criteria
cpe:2.3:a:radarcovid:radar-covid-backend-dp3t-server:*:*:*:*:*:*:*:*
< 1.0.7CPE matchmatch criteria
cpe:2.3:a:radarcovid:radarcovid:*:*:uniform_distribution:*:*:android:*:*
< 1.0.8CPE matchmatch criteria
cpe:2.3:a:radarcovid:radarcovid:*:*:uniform_distribution:*:*:iphone_os:*:*
< 1.1.0CPE matchmatch criteria
cpe:2.3:a:radarcovid:radarcovid:*:*:exponential_distribution:*:*:android:*:*
< 1.1.0CPE matchmatch criteria
cpe:2.3:a:radarcovid:radarcovid:*:*:exponential_distribution:*:*:iphone_os:*:*

CVSS Data

CVSS version used by this source: 3.1

7.4HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.65%
Probability of exploitation in next 30 days
EPSS Percentile
74.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0164 is in the 83rd percentile among its peer group of 707 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / DP-3T/documents/blob/master/DP3T%20-%20Best%20Practices%20for%20Operation%20Security%20in%20Proximity%20Tracing.pdf
ExploitThird Party Advisory
github.com / RadarCOVID/radar-covid-android/commit/09d00e5ede801ca400d45c7feda5a99c34e4176c
PatchThird Party Advisory
github.com / RadarCOVID/radar-covid-android/commit/53252773ffa81e116deabcbbea3bac96872b9888
PatchThird Party Advisory
github.com / RadarCOVID/radar-covid-android/commit/7fdc7debeb8a37faa77b53d9f9a1b4bbcff445ce
PatchThird Party Advisory
github.com / RadarCOVID/radar-covid-android/commit/8e5d14ec60e0c1847a4733556cf34d232c27102c
PatchThird Party Advisory
github.com / RadarCOVID/radar-covid-android/commit/91dcfff6252055637bc9ee0c46b8f003d64a16b9
PatchThird Party Advisory
github.com / RadarCOVID/radar-covid-android/commit/9627f4d69705bca68e550eefd3df1b9abe90b215
PatchThird Party Advisory
github.com / RadarCOVID/radar-covid-android/commit/ea0c4cc837f72f58e2b5df1ecf0899743ec3cdf8
PatchThird Party Advisory
github.com / RadarCOVID/radar-covid-backend-dp3t-server/commit/6d30c92cc8fcbde3ded7e9518853ef278080344d
PatchThird Party Advisory
github.com / RadarCOVID/radar-covid-backend-dp3t-server/commit/c37f81636250892670750e3989139fd76d4beffe
PatchThird Party Advisory
github.com / RadarCOVID/radar-covid-backend-dp3t-server/security/advisories/GHSA-w7jx-37x3-w2jx
Third Party Advisory
github.com / RadarCOVID/radar-covid-ios/commit/2d1505d4858642995ea09f02f23c953acaa65195
PatchThird Party Advisory