CVE-2026-92862
Received Received - Intake

Ticket Ryutsu Center URL Scheme Access Vulnerability

Vulnerability report for CVE-2026-92862, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: JPCERT/CC

Description

The Android application "Ticket Ryutsu Center" improperly handles custom URL schemes, allowing a malicious application to cause access to an arbitrary website via a crafted Intent.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Wavedash Co., Ltd. Ticket Ryutsu Center 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-939 The product uses a handler for a custom URL scheme, but it does not properly restrict which actors can invoke the handler using the scheme.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Android app Ticket Ryutsu Center mishandles custom URL schemes, enabling a malicious app to trigger an Intent that opens an arbitrary website without proper validation.

Detection Guidance

To detect this vulnerability, check if the Ticket Ryutsu Center app version is 4.1.9 or earlier. Look for suspicious intents or custom URL scheme handling in logs. Update to version 4.2.0 or later to mitigate risks.

Impact Analysis

An attacker could exploit this to redirect you to phishing sites, steal credentials, or deliver malware by tricking the app into opening malicious web content.

Compliance Impact

This vulnerability could potentially lead to unauthorized access to sensitive user data through phishing attacks, which may violate GDPR's data protection requirements or HIPAA's safeguards for protected health information if user data is exposed.

Mitigation Strategies

Update the Ticket Ryutsu Center application to the latest version to ensure proper handling of custom URL schemes. Avoid installing untrusted applications that may exploit this vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92862. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart