CVE-2026-22077
MEDIUMSensitive Information Disclosure Vulnerability Caused by Trusted Domain Bypass in OPPO Wallet
Title source: cnaDescription
OPPO Wallet APP contains a trusted domain validation flaw that allows attackers to bypass protected interface access restrictions, which may lead to account token hijacking and sensitive information disclosure.
Scores
CVSS v4
5.6
EPSS
0.0001
EPSS Percentile
0.6%
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/AU:N/R:A/V:D/RE:L/U:Amber
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-346
Status
published
Products (1)
OPPO/OPPO Wallet APP
all
Published
Apr 27, 2026
Tracked Since
Apr 27, 2026