CVE-2026-9222CWE-836
CVE-2026-9222
High · published June 26, 2026
What it is
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.
The record
Technical detail
- CVSS v3.1
- 8.1 · HIGH
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.00412 · 34.5th percentile
- Weakness
- CWE-836 · Use of Password Hash Instead of Password for Authentication
- Published
- 2026-06-26T04:16Z
References (1)
EPSS history
Timeline