CVE-2026-84283
Last modified
CVE-2026-84283 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-storage tree. A local application or file manager that has access to the relevant shared-storage path can enumerate, copy, and open those files without authenticating to Secure Folder.. EPSS estimates a 0.11% chance of exploitation in the next 30 days.
Description
Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-storage tree. A local application or file manager that has access to the relevant shared-storage path can enumerate, copy, and open those files without authenticating to Secure Folder.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| FluteCode | Secure Folder | 1.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-84283?
How severe is CVE-2026-84283?
How do I fix CVE-2026-84283?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-84270A flaw was found in the MTP backend in gvfs. When reading a …4.3
- CVE-2026-84279The Fancy Product Designer plugin for WordPress is vulnerabl…7.2
- CVE-2026-8428Concrete CMS 9.5.0 and below emits a CSRF token in the local…8.8
- CVE-2026-84280The Fancy Product Designer plugin for WordPress is vulnerabl…7.2
- CVE-2026-84281The Fancy Product Designer plugin for WordPress is vulnerabl…7.2
- CVE-2026-84282A Server-Side Request Forgery (SSRF) vulnerability exists in…6.5
- CVE-2026-84285An OS Command Injection vulnerability affecting Tuleap Enter…8.8
- CVE-2026-84287A flaw has been found in NousResearch hermes-agent 0.18.0. A…4.3
- CVE-2026-84288A vulnerability has been found in NousResearch hermes-agent …4.3
- CVE-2026-84289A vulnerability was found in NousResearch hermes-agent up to…4.3
- CVE-2026-8429SPIP versions prior to 4.4.14 contain a remote code executio…8.8
- CVE-2026-84292fast-uri serializes the port component of a URI without vali…7.5
Are you affected by CVE-2026-84283?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
