CVE-2026-47364: Infoleak
In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing opt-out. Impact: The Datadog user UUID and crash data are visible within Firebase Crashlytics. This UUID is not identifying outside Datadog's own systems.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Datadog Android applicationto a version that resolves this vulnerability.Fixed in v545-5.9.2 - Operational
After upgrading past v545-5.9.2, review Firebase Crashlytics datasets to ensure future crash reports are no longer tagged with Datadog user UUIDs.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47364?
The severity of CVE-2026-47364 is rated at 37.
How do I fix CVE-2026-47364?
To mitigate CVE-2026-47364, ensure to update the Datadog Android application to the latest version available.
What type of vulnerability is CVE-2026-47364?
CVE-2026-47364 is categorized as an information leak vulnerability.
What impact does CVE-2026-47364 have on user data?
CVE-2026-47364 may expose a user's Datadog UUID, linking it to the Firebase installation ID, potentially compromising user privacy.
When was CVE-2026-47364 published?
CVE-2026-47364 was published on August 7, 2026.