CVE-2026-92862: Medium severity Ticket Ryutsu Center vulnerability
Published Oct 8, 2026
·Updated
The Android application "Ticket Ryutsu Center" improperly handles custom URL schemes, allowing a malicious application to cause access to an arbitrary website via a crafted Intent.
Affected Software
1 affected component
Ticket Ryutsu Center
Event History
Oct 8, 2026
CVE Published
via MITRE·02:54 AM
Data Sourced
via MITRE·02:54 AM
DescriptionSeverity
Data Sourced
via NVD·03:16 AM
DescriptionSeverityWeakness
Event
via NVD·04:26 AM
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attack is local: a malicious Android application must send a crafted Intent. The supplied severity vector indicates no privileges are required, but user interaction is required.
2
How can I determine whether this applies to an installed application?
The affected application is Ticket Ryutsu Center, identified by the Android package ID jp.co.ticket in the provided Play Store reference.