Field notes
Writeups
AndroScope paper plus redacted field cases.
WPSniper — page-template LFI class
wordpressCVE-2026-87902. get_page_template include. VULN only on unique PEAR banner. Detect-only.
NextForge — Next.js class matrix
next.jsOne-file lab scanner. Profile App/Pages/middleware. Matching RCE / SSRF class. Curl + report snippet. Host stripped.
Bearer token on an unverified scheme
oauthServer 302 to a custom scheme carrying the access token. Chooser hijack. Vendor stripped.
Unauthenticated GitLab file-read
platformCVE-2026-85706. Workhorse miss, Puma route, File.open before auth. Classifier only.
Unclaimed ms-msa scheme
mobileCVE-2026-26123. Authenticator emitted ms-msa:// and did not claim it.
Reset-credentials ATO class
authCVE-2026-18963. Keycloak forgot-password. Unscoped selector plus unverified email action.
Empty join key, admin token
authCVE-2026-82329. Self-hosted Artifactory trusted a blank join key. No mint kit.
Provider selection is SQL
sqliExported ContentProvider glued selection into the query. Bind args unused.
DEX from a writable path
rceLoader mapped a file the extract path could overwrite. No payload DEX.
Bridge on the wrong origin
rceaddJavascriptInterface on a WebView that later loaded an extra URL.
Conscrypt owns the CA list
tlsMainline APEX store wins. User CA is a spectator. Observer only.
Wallet link, static client id
fintechStatic PIN client id, empty bot gate, unlink reset, emulator posture. Vendor stripped.
Intent redirection
mobileExported router starts a nested Intent. Safer Intents not armed.
FileProvider, root-path
mobilepaths.xml mapped /. grantUriPermissions on. No file read here.
WebView, intent://
mobileparseUri on a document URL, then startActivity.
The SDK exported the proxy
mobileMerged AAR activity. Host UID. Nested Intent sink.
Deeplink into the auth flow
mobileExported gate, no host allowlist, private AuthFlow on the other side.
Wireless debugging trust class
platformadbd can trust a LAN peer too soon. Observer only. CVE-2026-0073.
Hardcoded Entra token in public JS
webEmployee JWT with Admin role left in a dated dashboard bundle.
mTLS on the device
mobileAndroScope defense module. Software PKCS12 vs AndroidKeyStore. No public bypass kit.
Password in the query string
mobileRN login put the password in the URL. Error SDK copied it.
Custom scheme, no PKCE
mobileUnverified OAuth redirect plus no code_challenge.
AndroScope — the instrument
mobileRootless model, static engine, radar scoring, live-session rules.