CVE-2026-92862
Received
Received - Intake
Ticket Ryutsu Center URL Scheme Access Vulnerability
Vulnerability report for CVE-2026-92862, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-08
Last updated on: 2026-10-08
Assigner: JPCERT/CC
Description
Description
The Android application "Ticket Ryutsu Center" improperly handles custom URL schemes, allowing a malicious application to cause access to an arbitrary website via a crafted Intent.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Wavedash | Co., | Ltd. Ticket Ryutsu Center 0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-939 | The product uses a handler for a custom URL scheme, but it does not properly restrict which actors can invoke the handler using the scheme. |