CVE-2026-84283
Received Received - Intake

Secure Folder 1.2 Unencrypted File Storage Vulnerability

Vulnerability report for CVE-2026-84283, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: Fluid Attacks

Description

Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-storage tree. A local application or file manager that has access to the relevant shared-storage path can enumerate, copy, and open those files without authenticating to Secure Folder.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-25
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
flutecode secure_folder 1.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-922 The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-storage tree, specifically under the Documents directory. This allows any local application or file manager with access to shared storage to enumerate, copy, and open these files without authenticating to Secure Folder, bypassing the PIN gate.

Detection Guidance

Check the Documents directory in Android's shared storage for files with unusual names or extensions. Use a file manager to inspect the .SecureFolder or similar hidden directory. Look for files that should be encrypted but are stored unencrypted.

Impact Analysis

An attacker with file manager access or sufficient shared-storage permissions can read and copy vaulted files without the PIN. This defeats the confidentiality claims of the app, exposing sensitive data like photos, documents, contacts, notes, bank card details, and passwords to unauthorized access.

Compliance Impact

This vulnerability likely violates compliance with GDPR and HIPAA due to unauthorized access to unencrypted sensitive data stored in a public directory. GDPR requires protection of personal data, and HIPAA mandates safeguards for protected health information. The exposure of unencrypted files in shared storage undermines these requirements.

Mitigation Strategies

Stop using Secure Folder 1.2 immediately. Avoid storing sensitive files in the app until a patch is released. Use alternative encrypted storage solutions. Revoke unnecessary permissions for file managers or apps with shared storage access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84283. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart