๐Ÿ” CVE Alert

CVE-2026-5456

LOW 3.3

Align Technology My Invisalign App com.aligntech.myinvisalign.emea BuildConfig.java hard-coded key

CVSS Score
3.3
EPSS Score
0.0%
EPSS Percentile
1th

A vulnerability was identified in Align Technology My Invisalign App 3.12.4 on Android. The impacted element is an unknown function of the file com/aligntech/myinvisalign/BuildConfig.java of the component com.aligntech.myinvisalign.emea. The manipulation of the argument CDAACCESS_TOKEN leads to use of hard-coded cryptographic key . The attack must be carried out locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CWE CWE-321 CWE-320
Vendor align technology
Product my invisalign app
Published Apr 3, 2026
Last Updated Apr 3, 2026
Stay Ahead of the Next One

Get instant alerts for align technology my invisalign app

Be the first to know when new low vulnerabilities affecting align technology my invisalign app are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Align Technology / My Invisalign App
3.12.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/355044 vuldb.com: https://vuldb.com/vuln/355044/cti vuldb.com: https://vuldb.com/submit/781763 notion.so: https://www.notion.so/Contentful-CDA-Tokens-Exposure-Leading-to-Unauthorized-Access-to-Master-and-Release-Environments-in--3262de3f97fb802ebd1af88e1264cb9f?source=copy_link

Credits

๐Ÿ” fxizenta (VulDB User) VulDB CNA Team