CVE-2026-22077

MEDIUM

Sensitive Information Disclosure Vulnerability Caused by Trusted Domain Bypass in OPPO Wallet

Title source: cna
STIX 2.1

Description

OPPO Wallet APP contains a trusted domain validation flaw that allows attackers to bypass protected interface access restrictions, which may lead to account token hijacking and sensitive information disclosure.

Scores

CVSS v4 5.6
EPSS 0.0001
EPSS Percentile 0.6%
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/AU:N/R:A/V:D/RE:L/U:Amber

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-346
Status published
Products (1)
OPPO/OPPO Wallet APP all
Published Apr 27, 2026
Tracked Since Apr 27, 2026