{"id":"CVE-2026-84283","title":"Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-storage tree","summary":"Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-storage tree. A local application or file manager that has access to the relevant shared-storage path can enumerate, copy…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-922"],"vendor":"FluteCode","product":"Secure Folder","affected":["secure_folder 1.2"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T00:16:57.570","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84283","references":[{"url":"https://fluidattacks.com/advisories/sanguisugabogg","label":"help@fluidattacks.com"},{"url":"https://play.google.com/store/apps/details?id=com.securefolder.securevault","label":"help@fluidattacks.com"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-09-24T23:55:20.534Z","slug":"CVE-2026-84283","body":"## Overview\n\nSecure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-storage tree. A local application or file manager that has access to the relevant shared-storage path can enumerate, copy, and open those files without authenticating to Secure Folder.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}