Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-47363

Quick assessment

Affected
Datadog Android App
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Datadog是Datadog公司的一个数据监控平台。 Datadog 5.9.2之前版本存在权限许可和访问控制问题漏洞,该漏洞源于在Android App中AppActivity启动组件被声明为android:exported="true"且无权限保护,对Intent.getUserSession()的会话数据反序列化验证不当,导致任意已安装应用可注入特制会话数据并自动登录攻击者选择的身份,可能导致未经授权访问用户数据或执行未授权操作。

AI Predicted 8.6 Difficulty: Easy EPSS 0.14% · P4

Affected Version Matrix 1

VendorProduct Version RangeStatus
Datadog Android App 5.9.2< 5.9.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-47363

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from Intent extras with no permission guard, and signs the app into that session without validating it against the backend. This requires a malicious application co-installed on a device with the Datadog app installed, and an OAuth token the attacker is willing to load into the victim's app. Impact: A co-installed application can switch the victim's Datadog app to a session the attacker controls. This is an account-confusion issue; it does not by itself expose the victim's existing session or data.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-926
Source: CVE Program / CVE List V5
Vulnerability Title
Datadog 权限许可和访问控制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Datadog是Datadog公司的一个数据监控平台。 Datadog 5.9.2之前版本存在权限许可和访问控制问题漏洞,该漏洞源于在Android App中AppActivity启动组件被声明为android:exported="true"且无权限保护,对Intent.getUserSession()的会话数据反序列化验证不当,导致任意已安装应用可注入特制会话数据并自动登录攻击者选择的身份,可能导致未经授权访问用户数据或执行未授权操作。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Datadog Android App 5.9.2 ~ 5.9.2 -

II. Public POCs for CVE-2026-47363

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-47363

登录查看更多情报信息。

Other References for CVE-2026-47363 (1)

Same Patch Batch · Datadog · 2026-08-07 · 6 CVEs total

CVE-2026-47362 Datadog 授权问题漏洞
CVE-2026-47361 Datadog 权限许可和访问控制问题漏洞
CVE-2026-47364 Datadog 信息泄露漏洞
CVE-2026-44965 Datadog 权限许可和访问控制问题漏洞
CVE-2026-44964 Datadog 服务端请求伪造漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-47363

No comments yet


Leave a comment