๐Ÿ” CVE Alert

CVE-2026-47362

MEDIUM 4.6
CVSS Score
4.6
EPSS Score
0.0%
EPSS Percentile
0th

In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content in plaintext: LocalNotificationDatabase (notification title, message, recipient, service, tags, and on-call/incident deep links) and SearchRecentDatabase (the user's full in-app search history). Impact: Any actor able to bypass the app sandbox can read these databases in plaintext.

CWE CWE-922
Vendor datadog
Product android app
Published Aug 7, 2026
Last Updated Aug 8, 2026
Stay Ahead of the Next One

Get instant alerts for datadog android app

Be the first to know when new medium vulnerabilities affecting datadog android app are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Datadog / Android App
5.9.4 < 5.9.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
cwe.mitre.org: https://cwe.mitre.org/data/definitions/922.html zetetic.net: https://www.zetetic.net/sqlcipher/sqlcipher-for-android/ trust.datadoghq.com: https://trust.datadoghq.com/?tcuUid=2e8b8fa5-39ca-43f4-9f6a-aeafafb440ef

Credits

Mark Esler (https://github.com/eslerm)