๐Ÿ” CVE Alert

CVE-2026-26214

HIGH 7.4

Xiaomi Galaxy FDS Android SDK <= 3.0.8 TLS Hostname Verification Disabled Enables MITM

CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
0th

Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HTTPS is enabled (the default configuration). In GalaxyFDSClientImpl.createHttpClient(), the SDK configures Apache HttpClient with SSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER, which accepts any valid TLS certificate regardless of hostname mismatch. Because HTTPS is enabled by default in FDSClientConfiguration, all applications using the SDK with default settings are affected. This vulnerability allows a man-in-the-middle attacker to intercept and modify SDK communications to Xiaomi FDS cloud storage endpoints, potentially exposing authentication credentials, file contents, and API responses. The XiaoMi/galaxy-fds-sdk-android open source project has reached end-of-life status.

CWE CWE-297
Vendor xiaomi technology co., ltd.
Product galaxy fds android sdk
Published Feb 12, 2026
Last Updated Mar 3, 2026
Stay Ahead of the Next One

Get instant alerts for xiaomi technology co., ltd. galaxy fds android sdk

Be the first to know when new high vulnerabilities affecting xiaomi technology co., ltd. galaxy fds android sdk are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

Xiaomi Technology Co., Ltd. / Galaxy FDS Android SDK
0 โ‰ค 3.0.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/XavLimSG/Vulnerability-Research/blob/main/CVE-2026-26214/CVE-2026-26214.md github.com: https://github.com/XiaoMi/galaxy-fds-sdk-android vulncheck.com: https://www.vulncheck.com/advisories/xiaomi-galaxy-fds-android-sdk-tls-hostname-verification-disabled-enables-mitm

Credits

XavLimSG VulnCheck