CVE-2026-84283: FluteCode Secure Folder 1.2 -Plaintext vault files in shared storage bypass the PIN gate

Published Sep 24, 2026
·
Updated

Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-storage tree. A local application or file manager that has access to the relevant shared-storage path can enumerate, copy, and open those files without authenticating to Secure Folder.

Affected Software

1 affected component
FluteCode Secure Folder=1.2

Event History

Sep 24, 2026
CVE Published
via MITRE·11:41 PM
Data Sourced
via MITRE·11:41 PM
DescriptionWeakness
Sep 25, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can access files placed in the vault?

Any local application or file manager with access to the relevant Android shared-storage path can enumerate, copy, and open the vault files without authenticating to Secure Folder.

2

What access does an attacker need to exploit this issue?

The attacker needs local access through an Android application or file manager that can access the shared-storage location containing the vault files. No Secure Folder PIN authentication is required.

3

Are the affected vault files encrypted at rest?

No. Files selected for the password-protected vault are stored as unencrypted plaintext files in the Android shared-storage tree.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203