CVE-2026-107857
Received Received - Intake

Cloud Sync Credentials Stored in Plaintext in Mindwtr Mobile App

Vulnerability report for CVE-2026-107857, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Mindwtr is a free offline-first task management application for desktop and mobile. Prior to 1.1.5, the mobile application writes the Cloud sync bearer token and WebDAV password to unencrypted AsyncStorage under @mindwtr_cloud_token and @mindwtr_webdav_password. A party with access to the application database or an exposed device backup can recover these credentials and use them to access the user's synchronized tasks and attachments. This issue is fixed in version 1.1.5.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
dongdongbh Mindwtr < 1.1.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-312 The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in Mindwtr versions prior to 1.1.5 involves sensitive credentials being stored insecurely. The mobile app saves the Cloud sync bearer token and WebDAV password in unencrypted AsyncStorage under specific keys. This allows anyone with access to the app's database or device backup to retrieve these credentials and gain unauthorized access to the user's synchronized tasks and attachments.

Detection Guidance

Check if the mobile app version is below 1.1.5. Inspect the application database or device backup for unencrypted storage of @mindwtr_cloud_token and @mindwtr_webdav_password in AsyncStorage.

Impact Analysis

If you use Mindwtr on a mobile device, an attacker with access to your device's database or backup could steal your Cloud sync token and WebDAV password. This could let them view, modify, or delete your tasks and attachments without your knowledge.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA requirements for protecting personal and sensitive data. Unencrypted storage of credentials and potential unauthorized access to user data could lead to non-compliance, legal penalties, and loss of trust.

Mitigation Strategies

Update the Mindwtr mobile application to version 1.1.5 or later to fix the issue. If unable to update, avoid using cloud sync or WebDAV features until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107857. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart