CVE-2026-72506
Received Received - Intake

VoiceTra Application Incorrect Destination Channel Vulnerability

Vulnerability report for CVE-2026-72506, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: JPCERT/CC

Description

VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be directed to a server (or service) controlled by an attacker, potentially resulting in the theft of input data or the display of incorrect results.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
nict voicetra to 9.2.1 (exc)
nict voicetra 9.2.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-941 The product creates a communication channel to initiate an outgoing request to an actor, but it does not correctly specify the intended destination for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

VoiceTra, a multilingual speech translation app by NICT, has a vulnerability where communication channels incorrectly specify destinations. This flaw, CVE-2026-72506, could redirect users to attacker-controlled servers, risking data theft or incorrect results.

Detection Guidance

Detecting this vulnerability requires checking the installed version of VoiceTra on Android or iOS devices. Compare the app version against the patched version 9.2.1. No specific network commands are provided in the resources, but monitoring network traffic for unexpected redirects to untrusted servers may help identify exploitation attempts.

Impact Analysis

If exploited, this vulnerability may lead to stolen input data or display of incorrect translation results. Users of affected versions (Android/iOS 9.1.3 and 9.2.0) should update to version 9.2.1 to mitigate risks.

Compliance Impact

This vulnerability could potentially lead to data theft or incorrect results due to redirection to attacker-controlled servers. Such incidents may result in unauthorized access to sensitive user data, which could violate compliance requirements under GDPR (for personal data protection) and HIPAA (for protected health information).

Mitigation Strategies

Immediately update VoiceTra to version 9.2.1 or later via the App Store or Google Play. If using versions 9.1.3 or 9.2.0, uninstall the app until updated. Avoid using the service until the update is confirmed. No further mitigation steps are specified in the provided resources.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72506. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart