CVE-2026-0009

HIGH

Android 15-16 - Tapjacking Privilege Escalation

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-0009. PoCs published by cduram.

AI-analyzed exploit summary This PoC exploits a path traversal vulnerability (CWE-22) in NitroShare 0.3.4's LAN file transfer server, allowing unauthenticated attackers on the same LAN to write arbitrary files (e.g., to the Windows Startup folder) via crafted JSON item headers with traversal sequences in the 'name' field.

Description

In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Exploits (1)

github WORKING POC
by cduram · pythonpoc
https://github.com/cduram/NotCVE-2026-0009

This PoC exploits a path traversal vulnerability (CWE-22) in NitroShare 0.3.4's LAN file transfer server, allowing unauthenticated attackers on the same LAN to write arbitrary files (e.g., to the Windows Startup folder) via crafted JSON item headers with traversal sequences in the 'name' field.

Classification
Working Poc 99%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: nitroshare 0.3.4
No auth needed
Prerequisites: Attacker must be on the same LAN as the victim · NitroShare 0.3.4 must be running with default settings (no TLS/authentication)
mistral-large-3 · analyzed Jul 23, 2026 Full analysis →

Scores

CVSS v3 7.8
EPSS 0.0008
EPSS Percentile 0.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (4)
google/android 15.0
google/android 16.0
Google/Android 15
Google/Android 16
Published Jun 01, 2026
Tracked Since Jun 02, 2026