CVE-2026-5454
Hard-Coded Cryptographic Key in GRID Organiser App (Local Access
Publication date: 2026-04-03
Last updated on: 2026-04-03
Assigner: VulDB
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-320 | Key Management Errors |
| CWE-321 | The product uses a hard-coded, unchangeable cryptographic key. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the GRID Organiser App up to version 1.0.5 on Android. It involves a manipulation of the argument SegmentWriteKey in the file res/raw/app.json of the component co.gridapp.organiser, which leads to the use of a hard-coded cryptographic key. The attack requires local access to the device.
How can this vulnerability impact me? :
The impact of this vulnerability is limited due to its low CVSS scores (BaseScore 1.7 to 3.3) and the requirement for local access. However, the use of a hard-coded cryptographic key can potentially allow an attacker with local access to compromise the confidentiality of some data protected by this key.