CVE-2026-2974 is a local vulnerability in AliasVault App versions up to 0.25.3 on Android/iOS, where sensitive API session tokens in the shared_prefs/aliasvault.xml file can be exposed through backup manipulation. While this exposure does not directly compromise the encrypted vault (which requires the master password), it could allow an attacker with local access to gain unauthorized control over API sessions. The attack is considered difficult to exploit due to high complexity, but a public exploit exists. Despite the public exploit, there is no evidence of active exploitation or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.25.3CPE matchmatch criteria | cpe:2.3:a:aliasvault:aliasvault:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.