CVE-2026-86443: Cleartext Storage of Sensitive Information Vulnerability

Published Sep 16, 2026
·
Updated

Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an attacker with local access to the device to retrieve the credentials stored by the application and impersonate the user account.

Affected Software

1 affected component
DuoxMe<4.3.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade DuoxMe (Android) to a version that resolves this vulnerability.

    Fixed in 4.3.4
  2. Operational

    If DuoxMe credentials were stored prior to upgrading, rotate/revoke any exposed credentials because local attackers could have retrieved them and impersonated the user account.

Event History

Sep 16, 2026
CVE Published
via MITRE·09:12 AM
Data Sourced
via MITRE·09:12 AM
DescriptionWeakness

Frequently Asked Questions

1

Who is exposed to credential theft through this issue?

Users running DuoxMe for Android versions earlier than 4.3.4 are exposed if an attacker obtains local access to their device. The attacker can retrieve credentials stored by the application and impersonate the affected user account.

2

What level of access does an attacker need?

The issue requires local access to the Android device. The available information does not describe a remote exploitation path.

3

Which versions should be remediated?

DuoxMe for Android versions prior to 4.3.4 are affected. Updating to version 4.3.4 or later addresses the affected version range described.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203